CVE-2024-25168
SQL injection vulnerability in snow snow v.2.0.0 allows a remote attacker to execute arbitrary code via the dataScope pa
SQL injection vulnerability in snow v.2.0.0 allows a remote attacker to execute arbitrary code via the dataScope parameter of the system/role/list interface.
MEDIUM · CVSS 6.3
EPSS 0.01655
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0