Description
The CGE property management system contains SQL Injection vulnerabilities. Remote attackers can inject SQL commands into the parameters in Cookie and obtain data in the database without privilege.
No analysis available yet.
Remediation
Vendor Solution
Update CGE property management system to the latest version.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-9991 | The CGE property management system contains SQL Injection vulnerabilities. Remote attackers can inject SQL commands into the parameters in Cookie and obtain data in the database without privilege. |
References
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-17T01:51:39.534Z
Reserved: 2021-01-06T00:00:00.000Z
Link: CVE-2021-22856
No data.
Status : Modified
Published: 2021-02-17T11:15:15.443
Modified: 2026-06-17T03:37:53.367
Link: CVE-2021-22856
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
EUVD