PT-2019-13338 · Sertek · Sertek Xpare

Publicado

2019-07-17

·

Atualizado

2019-07-18

·

CVE-2019-13447

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Sertek Xpare version 3.67
Description An issue was discovered where the login form does not sanitize input data, allowing a malicious agent to potentially access the backend database via SQL injection.
Recommendations For Sertek Xpare version 3.67, consider implementing input sanitization for the login form to prevent SQL injection attacks. As a temporary workaround, restrict access to the login form and backend database to minimize the risk of exploitation.

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-13447

Produtos afetados

Sertek Xpare