{ "schema_version": "1.4.0", "id": "GHSA-rf28-62ww-gp4p", "modified": "2022-05-24T17:21:44Z", "published": "2022-05-24T17:21:44Z", "aliases": [ "CVE-2020-15308" ], "details": "Support Incident Tracker (aka SiT! or SiTracker) 3.67 p2 allows post-authentication SQL injection via the site_edit.php typeid or site parameter, the search_incidents_advanced.php search_title parameter, or the report_qbe.php criteriafield parameter.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-15308" }, { "type": "WEB", "url": "https://code610.blogspot.com/2020/06/postauth-sqli-in-sitracker-v367-p2.html" } ], "database_specific": { "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2020-06-26T11:15:00Z" } }