EVOLUCARE ECSIMAGING (aka ECS Imaging) through 6.21.5 has multiple SQL Injection issues in the login form and the password-forgotten form (such as /req_password_user.php?email=). This allows an attacker to steal data in the database and obtain access to the application. (The database component runs as root.) NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.exploit-db.com/exploits/49392 |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T16:45:51.257Z
Reserved: 2021-01-11T00:00:00
Link: CVE-2021-3118
No data.
Status : Modified
Published: 2021-01-11T06:15:13.320
Modified: 2024-11-21T06:20:55.387
Link: CVE-2021-3118
No data.
OpenCVE Enrichment
No data.
Weaknesses