CVE-2018-12977: Softexpert Excellence Suite
High severity, CVSS 8.8. EPSS: 1.4% chance of exploitation in the next 30 days.
A SQL injection vulnerability in the SoftExpert (SE) Excellence Suite 2.0 allows remote authenticated users to perform SQL heuristics by pulling information from the database with the "cddocument" parameter in the "Downloading Electronic Documents" section.
Affected products
- Softexpert Excellence Suite: version 2.0 only
Published 2018-07-09. Last modified 2026-06-17.