PT-2019-9572 · Cmg · Cmg Suite

Daniel Wong

·

Publicado

2019-04-25

·

Atualizado

2019-04-26

·

CVE-2018-18285

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CMG Suite versions 8.4 SP2 and earlier
Description The issue is related to SQL injection vulnerabilities due to insufficient input validation for the login interface. This could allow an unauthenticated attacker to conduct an SQL injection attack, potentially extracting sensitive information from the database and executing arbitrary scripts.
Recommendations For CMG Suite versions 8.4 SP2 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-18285

Produtos afetados

Cmg Suite