PT-2021-4507 · Opensips · Opensis

Nathan Johnson

·

Published

2021-09-01

·

Updated

2021-09-09

·

CVE-2021-39379

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions openSIS version 8.0
Description A SQL Injection issue exists, allowing a malicious attacker to issue SQL commands to the database through the password stn id parameter in ResetUserInfo.php. This can enable a remote attacker to execute arbitrary SQL queries.
Recommendations For openSIS version 8.0, consider restricting access to the ResetUserInfo.php endpoint until a patch is available, and avoid using the password stn id parameter in this endpoint to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05145
CVE-2021-39379

Affected Products

Opensis