vendor:
SD.NET RIM
by:
Fabian Mosch
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: SD.NET RIM
Affected Version From: < 4.7.3c
Affected Version To: < 4.7.3c
Patch Exists: NO
Related CWE:
CPE: a:sitzungsdienst:sd.net_rim:4.7.3c
Platforms Tested:
2019
SD.NET RIM 4.7.3c – ‘idtyp’ SQL Injection
SD.NET RIM before version 4.7.3c is vulnerable to a SQL-Injection vulnerability. An attacker can inject arbitrary SQL statements in the 'idtyp' parameter of a POST request to achieve remote code execution.
Mitigation:
Update to version 4.7.3c or later. Sanitize user input before executing SQL queries.