Changing MOTP (Mobile One Time Password) system’s specific function parameter has insufficient validation for user input. A attacker in local area network can perform SQL injection attack to read, modify or delete backend database without authentication.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.twcert.org.tw/tw/cp-132-5423-84a13-1.html |
History
No history.
MITRE
Status: PUBLISHED
Assigner: twcert
Published: 2021-12-29T07:15:16.708094Z
Updated: 2024-09-16T16:38:54.142Z
Reserved: 2021-11-23T00:00:00
Link: CVE-2021-44161
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-12-29T08:15:06.890
Modified: 2024-11-21T06:30:28.373
Link: CVE-2021-44161
Redhat
No data.