Vulnerabilities (CVE)

Filtered by vendor Aptean Subscribe
Filtered by product Product Configurator
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-26944 2 Aptean, Microsoft 2 Product Configurator, Windows 2024-02-28 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Aptean Product Configurator 4.61.0000 on Windows. A Time based SQL injection affects the nameTxt parameter on the main login page (aka cse?cmd=LOGIN). This can be exploited directly, and remotely.