PT-2020-13851 · Ozeki · Ozeki Ng Sms Gateway

Published

2020-09-22

·

Updated

2020-09-26

·

CVE-2020-14027

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ozeki NG SMS Gateway versions prior to 4.17.7
Description An issue was discovered where the database connection strings in Ozeki NG SMS Gateway accept custom unsafe arguments, such as ENABLE LOCAL INFILE, which can be used by attackers to enable MySQL Load Data Local attacks, potentially allowing a rogue MySQL server to be used.
Recommendations For Ozeki NG SMS Gateway versions prior to 4.17.7, update to version 4.17.7 or later to resolve the issue. As a temporary workaround, consider restricting the use of custom database connection string arguments to prevent exploitation.

Exploit

Fix

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-14027

Affected Products

Ozeki Ng Sms Gateway