CVE-2019-6986
28.01.2019, 15:29
SPARQL Injection in VIVO Vitro v1.10.0 allows a remote attacker to execute arbitrary SPARQL via the uri parameter, leading to a regular expression denial of service (ReDoS), as demonstrated by crafted use of FILTER%20regex in a /individual?uri= request.
Vendor | Product | Version |
---|---|---|
duraspace | vitro | 1.10.0 |
𝑥
= Vulnerable software versions
References