vendor:
TrainSmart
by:
Adrian Bondocea
7.5
CVSS
HIGH
SQL injection
89
CWE
Product Name: TrainSmart
Affected Version From: TrainSmart r1044
Affected Version To: TrainSmart r1044
Patch Exists: YES
Related CWE: CVE-2021-36520
CPE: a:itech:trainsmart:r1044
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=29561, https://www.infosecmatter.com/nessus-plugin-library/?id=27412, https://www.infosecmatter.com/nessus-plugin-library/?id=22896, https://www.infosecmatter.com/nessus-plugin-library/?id=24657, https://www.infosecmatter.com/nessus-plugin-library/?id=22940, https://www.infosecmatter.com/nessus-plugin-library/?id=24773, https://www.infosecmatter.com/nessus-plugin-library/?id=23626, https://www.infosecmatter.com/nessus-plugin-library/?id=22880, https://www.infosecmatter.com/nessus-plugin-library/?id=67417, https://www.infosecmatter.com/nessus-plugin-library/?id=27948
Platforms Tested: Linux
2023
itech TrainSmart r1044 – SQL injection
SQL injection vulnerability in itech TrainSmart r1044 allows remote attackers to view sensitive information via crafted command using sqlmap.
Mitigation:
Input validation and sanitization should be done to prevent SQL injection attacks.