vendor:
Virtua Cobranca 12S
by:
Luca Regne
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Virtua Cobranca 12S
Affected Version From: 12S
Affected Version To: 12S
Patch Exists: YES
Related CWE: CVE-2021-37589
CPE: a:virtuasoftware:virtua_cobranca_12s
Tags: cve,cve2021,virtua,sqli
CVSS Metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Nuclei Metadata: {'max-request': 3, 'shodan-query': 'http.favicon.hash:876876147', 'verified': True, 'vendor': 'virtuasoftware', 'product': 'cobranca'}
Platforms Tested: Windows Server 2019
2021
Virtua Software Cobranca 12S – SQLi
A Blind SQL injection vulnerability in a Login Page (/controller/login.php) in Virtua Cobranca 12S version allows remote unauthenticated attackers to get information about application executing arbitrary SQL commands by idusuario parameter.
Mitigation:
Virtua Software has released a patch to fix this vulnerability.