Description
The users’ data querying function of EIC e-document system does not filter the special characters which resulted in remote attackers can inject SQL syntax and execute arbitrary commands without privilege.
No analysis available yet.
Remediation
Vendor Solution
Update to version 3.0.4
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-9994 | The users’ data querying function of EIC e-document system does not filter the special characters which resulted in remote attackers can inject SQL syntax and execute arbitrary commands without privilege. |
References
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-16T23:01:27.719Z
Reserved: 2021-01-06T00:00:00.000Z
Link: CVE-2021-22859
No data.
Status : Modified
Published: 2021-03-17T09:15:12.093
Modified: 2024-11-21T05:50:46.873
Link: CVE-2021-22859
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD