Unknown · Simplessus · CVE-2017-20104
**Name of the Vulnerable Software and Affected Versions**
Simplessus version 3.7.7
**Description**
A critical issue affects the Cookie Handler component, where manipulation of the `UWA SID` argument leads to sql injection. This can be initiated remotely. The issue has been publicly disclosed and may be exploited.
**Recommendations**
For Simplessus version 3.7.7, upgrade to version 3.8.3 to address this issue. As a temporary workaround, consider restricting access to the Cookie Handler component until the upgrade is applied.