PT-2019-9572 · Cmg · Cmg Suite

Daniel Wong

·

Published

2019-04-25

·

Updated

2019-04-26

·

CVE-2018-18285

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CMG Suite versions 8.4 SP2 and earlier
Description The issue is related to SQL injection vulnerabilities due to insufficient input validation for the login interface. This could allow an unauthenticated attacker to conduct an SQL injection attack, potentially extracting sensitive information from the database and executing arbitrary scripts.
Recommendations For CMG Suite versions 8.4 SP2 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-18285

Affected Products

Cmg Suite