Vulnerabilities > Hexagongeospatial > Geomedia Webmap

DATE CVE VULNERABILITY TITLE RISK
2021-08-30 CVE-2021-37749 SQL Injection vulnerability in Hexagongeospatial Geomedia Webmap
MapService.svc in Hexagon GeoMedia WebMap 2020 before Update 2 (aka 16.6.2.66) allows blind SQL Injection via the Id (within sourceItems) parameter to the GetMap method.
network
low complexity
hexagongeospatial CWE-89
critical
10.0