CVE-2021-45788 Time-based SQL Injection was found in Metersphere v1.15.4 via the "orders" parameter.

A Cross-site scripting vulnerability was found in X-Rite’s iColor Passport v3.2.2 via the "password" parameter.

A SQL Injection was found in X-Rite’s iColor Passport v3.2.2 via the "password" parameter.

A SQL Injection was found in X-Rite’s iColor Passport v3.2.2 via the "password" parameter.

A cross-site scripting vulnerability was found in X-Rite’s iColor Passport v3.2.2 via the "password" parameter.

A SQL Injection was found in X-Rite’s iColor Passport v3.2.2 via the "password" parameter.

A SQL Injection was found in X-Rite’s iColor Passport v3.2.2 via the "password" parameter.

A SQL Injection was found in X-Rite’s iColor Passport v3.2.2 via the "password" parameter.

A SQL Injection was found in X-Rite’s iColor Passport v3.2.2 via the "password" parameter.

A SQL Injection was found in X-Rite’s iColor Passport v3.2.2 via the "password" parameter.

Products Affected

X-Rite’s iColor Passport v3.2.2 was affected by these vulnerabilities.

Timeline

Published on: 09/29/2022 03:15:00 UTC
Last modified on: 09/30/2022 16:52:00 UTC

References