vendor:
Web+Center
by:
Not available
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Web+Center
Affected Version From: 4.0.1
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Not available
CPE: a:web_center:web_center:4.0.1
Platforms Tested:
2004
SQL Injection Vulnerability in Web+Center
An SQL injection vulnerability is identified in the application that may allow attackers to pass malicious input to database queries, resulting in the modification of query logic or other attacks.
Mitigation:
The vendor should sanitize user-supplied input to prevent SQL injection attacks. Users are advised to update to the latest version of the application.