Vulnerabilities > Fireeye > Email Malware Protection System > 8.4.3.908134

DATE CVE VULNERABILITY TITLE RISK
2020-10-26 CVE-2020-25034 SQL Injection vulnerability in Fireeye Email Malware Protection System 8.4.3.908134
eMPS prior to eMPS 9.0 FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the sort, sort_by, search{URL], or search[attachment] parameter to the email search feature.
network
low complexity
fireeye CWE-89
6.5