GRANDCOM DynWEB before 4.2 contains a SQL Injection vulnerability in the admin login interface. A remote unauthenticated attacker can exploit this vulnerability to obtain administrative access to the webpage, access the user database, modify web content and upload custom files. The backend login script does not verify and sanitize user-provided strings.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2022-05-19T14:59:45

Updated: 2024-08-04T01:16:03.994Z

Reserved: 2021-07-23T00:00:00

Link: CVE-2021-37413

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-05-19T15:15:07.873

Modified: 2022-06-01T19:36:47.227

Link: CVE-2021-37413

cve-icon Redhat

No data.