PT-2026-3172 · Vianeos · Vianeos Octopus 5
CVE-2021-47801
·
Publicado
2026-01-15
·
Atualizado
2026-01-16
CVSS v3.1
8.2
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Vianeos OctoPUS 5
Description
The software contains a time-based blind SQL injection issue in the
login user parameter during authentication requests. An attacker can exploit this by sending malicious POST requests with crafted SQL payloads that trigger database sleep functions to extract information. The vulnerable parameter is used during authentication.Recommendations
Apply input validation and sanitization to the
login user parameter to prevent the injection of malicious SQL code.Exploit
Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Vianeos Octopus 5