CVE-2020-36768 - CVE House
Back to Database
Status published High CVE-2020-36768

rl-institut NESP2 database.py sql injection

Vulnerability Description

A vulnerability was found in rl-institut NESP2 Initial Release/1.0. It has been classified as critical. Affected is an unknown function of the file app/database.py. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The patch is identified as 07c0cdf36cf6a4345086d07b54423723a496af5e. It is recommended to apply a patch to fix this issue. VDB-246642 is the identifier assigned to this vulnerability.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-36768

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • VulDB GitHub Commit Analyzer

Affected Vendor

rl-institut

View all reports →

Affected Software

NESP2
Vulnerable Versions:
1.0, Initial Release

Timeline

Official Publish: December 3rd, 2023
Last Modified: August 4th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Weaknesses (CWE)