CVE-2019-6986
EUVD-2022-414628.01.2019, 15:29
SPARQL Injection in VIVO Vitro v1.10.0 allows a remote attacker to execute arbitrary SPARQL via the uri parameter, leading to a regular expression denial of service (ReDoS), as demonstrated by crafted use of FILTER%20regex in a /individual?uri= request.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| duraspace | vitro | 1.10.0 |
𝑥
= Vulnerable software versions
References