PT-2020-14116 · Connectwise · Connectwise Automate

Jason Slagle

·

Published

2020-07-07

·

Updated

2020-07-16

·

CVE-2020-15008

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Connectwise Automate versions prior to 2020.7 Connectwise Automate versions prior to 2019.12
Description A SQL Injection issue exists in the probe code due to inadequate server-side validation, allowing arbitrary update commands to be run by modifying the table name. The code creates dynamic SQL for the insert statement and utilizes the user-supplied table name with little validation. Other SQL injection techniques, such as timing attacks, can be used to perform full data extraction.
Recommendations For versions prior to 2020.7, update to version 2020.7 or later. For versions prior to 2019.12, apply the hotfix for 2019.12. As a temporary workaround, consider restricting access to the probe implementation to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15008

Affected Products

Connectwise Automate