Vulnerabilities > Snowsoftware > Snow License Manager

DATE CVE VULNERABILITY TITLE RISK
2023-08-11 CVE-2023-3864 SQL Injection vulnerability in Snowsoftware Snow License Manager 9.27/9.29/9.30
Blind SQL injection in a service running in Snow Software license manager from version 8.0.0 up to and including 9.30.1 on Windows allows a logged in user with high privileges to inject SQL commands via the web portal.
network
low complexity
snowsoftware CWE-89
7.2
2023-08-11 CVE-2023-3937 Cross-site Scripting vulnerability in Snowsoftware Snow License Manager 9.27/9.29/9.30
Cross site scripting vulnerability in web portal in Snow Software License Manager from version 9.0.0 up to and including 9.30.1 on Windows allows an authenticated user with high privileges to trigger cross site scripting attack via the web browser
network
low complexity
snowsoftware CWE-79
4.8
2023-05-17 CVE-2023-2679 Unspecified vulnerability in Snowsoftware Snow License Manager
Data leakage in Adobe connector in Snow Software SPE 9.27.0 on Windows allows privileged user to observe other users data.
network
low complexity
snowsoftware
4.3
2022-05-18 CVE-2022-0883 Unquoted Search Path or Element vulnerability in Snowsoftware Snow License Manager
SLM has an issue with Windows Unquoted/Trusted Service Paths Security Issue.
local
low complexity
snowsoftware CWE-428
4.6