PT-2021-22156 · Auvesy · Versiondog

Amir Preminger

·

Published

2021-10-22

·

Updated

2021-10-27

·

CVE-2021-38481

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions No specific software or versions are mentioned in the provided descriptions.
Description The scheduler service, which runs on a specific TCP port, allows users to start and stop jobs. However, it does not sanitize the supplied JOB ID provided to the function. This lack of sanitation enables an attacker to send a malicious payload, potentially allowing the execution of another SQL expression by sending a specific string.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-38481

Affected Products

Versiondog