PT-2019-9573 · Cmg · Cmg Suite

Daniel Wong

·

Published

2019-04-25

·

Updated

2019-04-26

·

CVE-2018-18286

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CMG Suite versions 8.4 SP2 and earlier
Description The issue is related to SQL injection vulnerabilities due to insufficient input validation for the changepwd interface. This could allow an unauthenticated attacker to conduct an SQL injection attack, potentially extracting sensitive information from the database and executing arbitrary scripts.
Recommendations For CMG Suite versions 8.4 SP2 and earlier, update to a version that addresses the SQL injection vulnerabilities in the changepwd interface to prevent exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-18286

Affected Products

Cmg Suite