Emuse - eServices / eNvoice SQL injection can be used in various ways ranging from bypassing login authentication or dumping the whole database to full RCE on the affected endpoints. The SQLi caused by CWE-209: Generation of Error Message Containig Sensetive Information, showing parts of the aspx code and the webroot location , information an attacker can leverage to further compromise the host.
History

Mon, 16 Sep 2024 18:45:00 +0000

Type Values Removed Values Added
Title Emuse - eServices / eNvoice SQL injection Emuse - eServices / eNvoice SQL injection

cve-icon MITRE

Status: PUBLISHED

Assigner: INCD

Published: 2021-12-29T14:13:38.766729Z

Updated: 2024-09-16T18:38:48.510Z

Reserved: 2021-07-12T00:00:00

Link: CVE-2021-36722

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-12-29T15:15:07.757

Modified: 2022-01-11T14:12:33.257

Link: CVE-2021-36722

cve-icon Redhat

No data.