CVE-2018-6792: Saifor Cvms Hub

High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.

Multiple SQL injection vulnerabilities in Saifor CVMS HUB 1.3.1 allow an authenticated user to execute arbitrary SQL commands via multiple parameters to the /cvms-hub/privado/seccionesmib/secciones.xhtml resource. The POST parameters are j_idt118, j_idt120, j_idt122, j_idt124, j_idt126, j_idt128, and j_idt130 under formularioGestionarSecciones:tablaSeccionesMib:*:filter. The GET parameter is nombreAgente.

Affected products

  • Saifor Cvms Hub: version 1.3.1 only

Published 2018-02-07. Last modified 2026-06-17.