PT-2019-12898 · Auo · Auo Sunveillance Monitoring System

Published

2019-11-12

·

Updated

2019-11-15

·

CVE-2019-12720

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions AUO SunVeillance Monitoring System versions prior to 1.1.9e
Description The issue allows an attacker to carry a SQL Injection payload to the server, enabling them to read privileged data. This is possible through several parameters, including MailAdd in "mvc send mail.aspx", plant no in "picture manage mvc.aspx" and "swapdl mvc.aspx", and Text Postal Code and Text Dis Code in "account management.aspx".
Recommendations For versions prior to 1.1.9e, update to version 1.1.9e or later to resolve the issue. As a temporary workaround, consider restricting access to the affected API endpoints, such as "mvc send mail.aspx", "picture manage mvc.aspx", "swapdl mvc.aspx", and "account management.aspx", to minimize the risk of exploitation. Avoid using the vulnerable parameters MailAdd, plant no, Text Postal Code, and Text Dis Code in the affected endpoints until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-12720

Affected Products

Auo Sunveillance Monitoring System