The CGE property management system contains SQL Injection vulnerabilities. Remote attackers can inject SQL commands into the parameters in Cookie and obtain data in the database without privilege.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: twcert
Published: 2021-02-17T10:45:28.427313Z
Updated: 2024-09-17T01:51:39.534Z
Reserved: 2021-01-06T00:00:00
Link: CVE-2021-22856
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-02-17T11:15:15.443
Modified: 2024-11-21T05:50:46.497
Link: CVE-2021-22856
Redhat
No data.