PT-2019-17831 · Portier · Portier Vision

Christian Pappas

·

Published

2019-03-19

·

Updated

2019-03-22

·

CVE-2019-5722

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions portier vision versions 4.4.4.2 through 4.4.4.6
Description The issue is related to a lack of user input validation in parameter handling, which leads to SQL injections. This affects the login form and the search form for a key ring number.
Recommendations For versions 4.4.4.2 through 4.4.4.6, consider validating user input to prevent SQL injections as a temporary workaround until a patch is available. Restrict access to the login and search forms to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-5722

Affected Products

Portier Vision