vendor:
SoftExpert Excellence Suite
by:
Seren PORSUK
8.8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: SoftExpert Excellence Suite
Affected Version From: 2.0
Affected Version To: 2.0
Patch Exists: NO
Related CWE: N/A
CPE: softexpert:softexpert_excellence_suite
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: PHP
2018
SoftExpert Excellence Suite 2.0 – ‘cddocument’ SQL Injection
A SQL injection vulnerability in the SoftExpert (SE) Excellence Suite 2.0 allows remote authenticated users to perform SQL heuristics by pulling information from the database with the 'cddocument' parameter in the 'Downloading Electronic Documents' section.
Mitigation:
Input validation and sanitization should be used to prevent SQL injection attacks.