CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 7.5. It may be remotely exploitable. It involves a SQL injection risk.
CVE
CVE-2014-2737
Severity
HIGH
CVSS
7.5
EPSS
1.16%
Original NVD Description
SQL injection vulnerability in the get_active_session function in the KTAPI_UserSession class in webservice/clienttools/services/mdownload.php in KnowledgeTree 3.7.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the u parameter, related to the getFileName function.