PT-2021-21326 · Emuse · Emuse

Published

2021-12-29

·

Updated

2022-01-11

·

CVE-2021-36722

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Emuse - eServices / eNvoice (affected versions not specified)
Description The issue allows for SQL injection, which can be utilized in various ways, including bypassing login authentication, dumping the database, or achieving full remote code execution (RCE) on affected endpoints. This is caused by the generation of error messages containing sensitive information, such as parts of the aspx code and the webroot location, which an attacker can leverage to further compromise the host.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-36722

Affected Products

Emuse