Description
Changing MOTP (Mobile One Time Password) system’s specific function parameter has insufficient validation for user input. A attacker in local area network can perform SQL injection attack to read, modify or delete backend database without authentication.
No analysis available yet.
Remediation
Vendor Solution
Contact tech support from Changing.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-31011 | Changing MOTP (Mobile One Time Password) system’s specific function parameter has insufficient validation for user input. A attacker in local area network can perform SQL injection attack to read, modify or delete backend database without authentication. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-5423-84a13-1.html |
|
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-16T16:38:54.142Z
Reserved: 2021-11-23T00:00:00.000Z
Link: CVE-2021-44161
No data.
Status : Modified
Published: 2021-12-29T08:15:06.890
Modified: 2024-11-21T06:30:28.373
Link: CVE-2021-44161
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD