CVE-2020-37105 | redmine PMB 5.6 Requests download.php logid sql injection (Exploit 48356 / EUVD-2020-30987)
A vulnerability described as critical has been identified in redmine PMB 5.6. This impacts an unknown function of the file /admin/sauvegarde/download.php of the component Requests Handler. The manipulation of the argument logid results in sql injection.
This vulnerability is cataloged as CVE-2020-37105. The attack may be launched remotely. Furthermore, there is an exploit available.