PT-2019-9573 · Cmg · Cmg Suite

Daniel Wong

·

Publicado

2019-04-25

·

Atualizado

2019-04-26

·

CVE-2018-18286

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CMG Suite versions 8.4 SP2 and earlier
Description The issue is related to SQL injection vulnerabilities due to insufficient input validation for the changepwd interface. This could allow an unauthenticated attacker to conduct an SQL injection attack, potentially extracting sensitive information from the database and executing arbitrary scripts.
Recommendations For CMG Suite versions 8.4 SP2 and earlier, update to a version that addresses the SQL injection vulnerabilities in the changepwd interface to prevent exploitation.

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-18286

Produtos afetados

Cmg Suite