CVE-2020-36768

Source
https://nvd.nist.gov/vuln/detail/CVE-2020-36768
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-36768.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2020-36768
Published
2023-12-03T11:15:08.443Z
Modified
2025-11-14T11:07:37.050957Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A vulnerability was found in rl-institut NESP2 Initial Release/1.0. It has been classified as critical. Affected is an unknown function of the file app/database.py. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The patch is identified as 07c0cdf36cf6a4345086d07b54423723a496af5e. It is recommended to apply a patch to fix this issue. VDB-246642 is the identifier assigned to this vulnerability.

References

Affected packages

Git / github.com/rl-institut/nesp2

Affected ranges

Type
GIT
Repo
https://github.com/rl-institut/nesp2
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

0.*

0.0.1

Other

working_state