Vulnerabilities > Snowsoftware > Snow License Manager > 9.30
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-08-11 | CVE-2023-3864 | SQL Injection vulnerability in Snowsoftware Snow License Manager 9.27/9.29/9.30 Blind SQL injection in a service running in Snow Software license manager from version 8.0.0 up to and including 9.30.1 on Windows allows a logged in user with high privileges to inject SQL commands via the web portal. | 7.2 |
2023-08-11 | CVE-2023-3937 | Cross-site Scripting vulnerability in Snowsoftware Snow License Manager 9.27/9.29/9.30 Cross site scripting vulnerability in web portal in Snow Software License Manager from version 9.0.0 up to and including 9.30.1 on Windows allows an authenticated user with high privileges to trigger cross site scripting attack via the web browser | 4.8 |