Vulnerabilities > Snowsoftware > Snow License Manager > High

DATE CVE VULNERABILITY TITLE RISK
2023-08-11 CVE-2023-3864 SQL Injection vulnerability in Snowsoftware Snow License Manager 9.27/9.29/9.30
Blind SQL injection in a service running in Snow Software license manager from version 8.0.0 up to and including 9.30.1 on Windows allows a logged in user with high privileges to inject SQL commands via the web portal.
network
low complexity
snowsoftware CWE-89
7.2
2022-05-18 CVE-2022-0883 Unquoted Search Path or Element vulnerability in Snowsoftware Snow License Manager
SLM has an issue with Windows Unquoted/Trusted Service Paths Security Issue.
local
low complexity
snowsoftware CWE-428
7.8