PT-2020-14116 · Connectwise · Connectwise Automate
Jason Slagle
·
Published
2020-07-07
·
Updated
2020-07-16
·
CVE-2020-15008
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Connectwise Automate versions prior to 2020.7
Connectwise Automate versions prior to 2019.12
Description
A SQL Injection issue exists in the probe code due to inadequate server-side validation, allowing arbitrary update commands to be run by modifying the table name. The code creates dynamic SQL for the insert statement and utilizes the user-supplied table name with little validation. Other SQL injection techniques, such as timing attacks, can be used to perform full data extraction.
Recommendations
For versions prior to 2020.7, update to version 2020.7 or later.
For versions prior to 2019.12, apply the hotfix for 2019.12.
As a temporary workaround, consider restricting access to the probe implementation to minimize the risk of exploitation.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Connectwise Automate