PT-2022-11509 · Unknown · Teammate+ Audit
Published
2022-06-06
·
Updated
2022-06-13
·
CVE-2021-41932
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TeamMate+ Audit version 28.0.19.0
Description
A blind SQL injection vulnerability in the search form allows any authenticated user to create malicious SQL injections. This can result in complete database compromise, gaining information about other users, and unauthorized access to audit data.
Recommendations
For TeamMate+ Audit version 28.0.19.0, consider disabling the search form functionality until a patch is available to prevent malicious SQL injections. Restrict access to the search form to minimize the risk of exploitation. Avoid using the search form with user-supplied input until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Teammate+ Audit