PT-2022-11509 · Unknown · Teammate+ Audit

Published

2022-06-06

·

Updated

2022-06-13

·

CVE-2021-41932

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TeamMate+ Audit version 28.0.19.0
Description A blind SQL injection vulnerability in the search form allows any authenticated user to create malicious SQL injections. This can result in complete database compromise, gaining information about other users, and unauthorized access to audit data.
Recommendations For TeamMate+ Audit version 28.0.19.0, consider disabling the search form functionality until a patch is available to prevent malicious SQL injections. Restrict access to the search form to minimize the risk of exploitation. Avoid using the search form with user-supplied input until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41932

Affected Products

Teammate+ Audit