vendor:
eScan Management Console
by:
Sahil Ojha
7.2
CVSS
HIGH
SQL Injection
89
CWE
Product Name: eScan Management Console
Affected Version From: 14.0.1400.2281
Affected Version To: 14.0.1400.2281
Patch Exists: NO
Related CWE: CVE-2023-31702
CPE: ewconsole.dll
Platforms Tested: Windows
2023
eScan Management Console 14.0.1400.2281 – SQL Injection (Authenticated)
Authenticated SQL Injection vulnerability in eScan Management Console version 14.0.1400.2281 allows an attacker to execute arbitrary SQL commands through the 'UsrId' parameter in the GetUserCurrentPwd function, leading to unauthorized access to the database and potential remote code execution.
Mitigation:
Apply the vendor-supplied patch or update to the latest version of eScan Management Console. Ensure that all user-supplied input is properly validated and sanitized to prevent SQL injection attacks.