vendor:
Sahi Pro
by:
Goutham Madhwaraj
9.8
CVSS
CRITICAL
SQL Injection
89
CWE
Product Name: Sahi Pro
Affected Version From: 7.x.x
Affected Version To: 8.0.0
Patch Exists: YES
Related CWE: CVE-2018-20469
CPE: a:sahi_technologies:sahi_pro
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10
2019
Sahi pro ( <= 8.x ) sensitive information disclosure by SQL injection
An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A parameter in the web reports module is vulnerable to SQL injection. This can be exploited to inject SQL queries and run standard h2 system functions.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in SQL queries.