PT-2021-22936 · Unknown · Opensis Classic
Minhgalaxy
·
Published
2021-10-12
·
Updated
2021-10-19
·
CVE-2021-40618
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
openSIS Classic version 8.0
Description
An SQL Injection issue exists via the
ADDR CONT USRN, ADDR CONT PSWD, SECN CONT USRN, or SECN CONT PSWD parameters in HoldAddressFields.php. This allows for potential exploitation of the SQL injection vulnerability.Recommendations
For openSIS Classic version 8.0, consider restricting access to the HoldAddressFields.php file or the vulnerable parameters
ADDR CONT USRN, ADDR CONT PSWD, SECN CONT USRN, and SECN CONT PSWD to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opensis Classic