{ "schema_version": "1.4.0", "id": "GHSA-fpcm-j34w-8cjw", "modified": "2022-05-24T17:00:43Z", "published": "2022-05-24T17:00:43Z", "aliases": [ "CVE-2019-12720" ], "details": "AUO SunVeillance Monitoring System before v1.1.9e is vulnerable to mvc_send_mail.aspx (MailAdd parameter) SQL Injection. An Attacker can carry a SQL Injection payload to the server, allowing the attacker to read privileged data. This also affects the picture_manage_mvc.aspx plant_no parameter, the swapdl_mvc.aspx plant_no parameter, and the account_management.aspx Text_Postal_Code and Text_Dis_Code parameters.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-12720" }, { "type": "WEB", "url": "https://drive.google.com/file/d/1QYgj4FU0MjSIhgXwddg4L5no9KYn8E9v/view" }, { "type": "WEB", "url": "https://www.exploit-db.com/exploits/47542" } ], "database_specific": { "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2019-11-12T19:15:00Z" } }