The users’ data querying function of EIC e-document system does not filter the special characters which resulted in remote attackers can inject SQL syntax and execute arbitrary commands without privilege.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2021-03-17T09:10:30.761178Z

Updated: 2024-09-16T23:01:27.719Z

Reserved: 2021-01-06T00:00:00

Link: CVE-2021-22859

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-03-17T09:15:12.093

Modified: 2021-03-23T15:48:20.127

Link: CVE-2021-22859

cve-icon Redhat

No data.