PT-2022-11959 · Digium · Quicklert For Digium
Nick Berrie
·
Published
2022-03-07
·
Updated
2022-03-15
·
CVE-2021-43969
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Quicklert for Digium version 10.0.0 (1043)
Description
The issue affects the login.jsp page, allowing for Blind SQL Injection with Out-of-Band Interaction (DNS) and Blind Time-Based SQL Injections. This can be exploited to disclose all data within the database, including administrative accounts' login IDs and passwords, via the
uname parameter in the login.jsp page.Recommendations
For Quicklert for Digium version 10.0.0 (1043), consider restricting access to the login.jsp page until a fix is available. As a temporary workaround, avoid using the
uname parameter in the login.jsp page to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Quicklert For Digium