vendor:
Jelastic
by:
Procode701
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Jelastic
Affected Version From: 5.4
Affected Version To: 5.4
Patch Exists: NO
Related CWE: N/A
CPE: a:jelastic:jelastic
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Kali Linux
[date]
Jelastic 5.4 – ‘host’ SQL injection
The application /1.0/users/authentication/rest/signin is vulnerable to SQL injection. Vulnerable application Header field: Host:' AND 8494=8494-- ttWV. Payload:' AND 8494=8494-- ttWV.
Mitigation:
Input validation and sanitization should be done to prevent SQL injection attacks.