CAYIN xPost suffers from an unauthenticated SQL Injection vulnerability. Input passed via the GET parameter 'wayfinder_seqid' in wayfinder_meeting_input.jsp is not properly sanitized before being returned to the user or used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code and execute SYSTEM commands.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: rapid7

Published: 2020-08-06T15:45:28.016670Z

Updated: 2024-09-17T03:37:28.730Z

Reserved: 2020-01-21T00:00:00

Link: CVE-2020-7356

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-08-06T16:15:13.577

Modified: 2020-08-12T13:39:55.297

Link: CVE-2020-7356

cve-icon Redhat

No data.