CVE-2020-28860: Openasset Digital Asset Management
High severity, CVSS 8.8. EPSS: 2.2% chance of exploitation in the next 30 days.
OpenAssetDigital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied input, incorporating it into its SQL queries, allowing for authenticated blind SQL injection.
Affected products
- Openasset Digital Asset Management: up to and including 12.0.19
Published 2020-12-14. Last modified 2026-07-09.