PT-2019-13338 · Sertek · Sertek Xpare

Published

2019-07-17

·

Updated

2019-07-18

·

CVE-2019-13447

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Sertek Xpare version 3.67
Description An issue was discovered where the login form does not sanitize input data, allowing a malicious agent to potentially access the backend database via SQL injection.
Recommendations For Sertek Xpare version 3.67, consider implementing input sanitization for the login form to prevent SQL injection attacks. As a temporary workaround, restrict access to the login form and backend database to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-13447

Affected Products

Sertek Xpare