PT-2021-15229 · Unknown · Cge Property Management System

Jia-Rong Chen

·

Published

2021-02-17

·

Updated

2021-02-25

·

CVE-2021-22856

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CGE property management system (affected versions not specified)
Description The issue concerns SQL Injection vulnerabilities in the CGE property management system. Remote attackers can inject SQL commands into the parameters in the Cookie and obtain data in the database without privilege.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-22856

Affected Products

Cge Property Management System