PT-2021-18756 · Sysaid · Sysaid

B3Ta

·

Published

2021-07-22

·

Updated

2021-07-31

·

CVE-2021-30486

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SysAid version 20.3.64 b14
Description The issue is related to Blind and Stacker SQL injection. It can be exploited via several API endpoints, including "AssetManagementChart.jsp" with computerID or group1 parameters, "AssetManagementList.jsp" with computerID or group1 parameters, and "AssetManagementSummary.jsp" with the group1 parameter.
Recommendations For SysAid version 20.3.64 b14, consider disabling access to the vulnerable API endpoints, such as "AssetManagementChart.jsp", "AssetManagementList.jsp", and "AssetManagementSummary.jsp", until a patch is available. Restrict the use of the computerID and group1 parameters in these endpoints to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-30486

Affected Products

Sysaid