vendor:
ELOenterprise 10
by:
Jens Regel
8.8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: ELOenterprise 10
Affected Version From: ELOenterprise 10 (ELO Access Manager <= 10.17.120)
Affected Version To: ELOprofessional 9 (ELO Access Manager <= 9.17.120)
Patch Exists: NO
Related CWE: N/A
CPE: a:elo:elo_enterprise_10
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
Elektronischer Leitz-Ordner 10 – SQL Injection
We have discovered a time-based blind SQL injection vulnerability in the ELO Access Manager (<= 9.17.120 and <= 10.17.120) component that makes it possible to read all database content. The vulnerability exists in the HTTP GET parameter 'ticket'. For example, we succeeded in reading the password hash of the administrator user in the 'userdata' table from the 'eloam' database.
Mitigation:
Ensure that all user-supplied input is validated and sanitized before being used in a SQL query.