PT-2021-22936 · Unknown · Opensis Classic

Minhgalaxy

·

Published

2021-10-12

·

Updated

2021-10-19

·

CVE-2021-40618

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions openSIS Classic version 8.0
Description An SQL Injection issue exists via the ADDR CONT USRN, ADDR CONT PSWD, SECN CONT USRN, or SECN CONT PSWD parameters in HoldAddressFields.php. This allows for potential exploitation of the SQL injection vulnerability.
Recommendations For openSIS Classic version 8.0, consider restricting access to the HoldAddressFields.php file or the vulnerable parameters ADDR CONT USRN, ADDR CONT PSWD, SECN CONT USRN, and SECN CONT PSWD to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-40618

Affected Products

Opensis Classic