CyberRota Analysis
AI analysis pending.
CVE
CVE-2020-13525
Severity
HIGH
CVSS
8.8
EPSS
1.68%
Original NVD Description
The sort parameter in the download page /sysworkflow/en/neoclassic/reportTables/reportTables_Ajax is vulnerable to SQL injection in ProcessMaker 3.4.11. A specially crafted HTTP request can cause an SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.