PT-2020-17174 · Egavilanmedia · Egavilanmedia Ecm Address Book

Published

2020-12-24

·

Updated

2021-04-22

·

CVE-2020-29474

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions EGavilan Media EGM Address Book version 1.0
Description The issue allows an attacker to gain Admin Panel access using malicious SQL injection queries, potentially leading to remote arbitrary code execution.
Recommendations For EGavilan Media EGM Address Book version 1.0, consider restricting access to the Admin Panel until a patch is available. As a temporary workaround, avoid using user-input data in SQL queries to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-29474

Affected Products

Egavilanmedia Ecm Address Book