CVE-2021-22856

The CGE property management system contains SQL Injection vulnerabilities. Remote attackers can inject SQL commands into the parameters in Cookie and obtain data in the database without privilege.
Configurations

Configuration 1 (hide)

cpe:2.3:a:changjia_property_management_system_project:changjia_property_management_system:1.00:*:*:*:*:*:*:*

History

21 Nov 2024, 05:50

Type Values Removed Values Added
CVSS v2 : 5.0
v3 : 7.5
v2 : 5.0
v3 : 9.8
References () https://www.chtsecurity.com/news/fe1e30ef-4dac-4848-a3c9-a7df12672422 - Third Party Advisory () https://www.chtsecurity.com/news/fe1e30ef-4dac-4848-a3c9-a7df12672422 - Third Party Advisory
References () https://www.twcert.org.tw/tw/cp-132-4394-76d41-1.html - Third Party Advisory () https://www.twcert.org.tw/tw/cp-132-4394-76d41-1.html - Third Party Advisory

Information

Published : 2021-02-17 11:15

Updated : 2024-11-21 05:50


NVD link : CVE-2021-22856

Mitre link : CVE-2021-22856

CVE.ORG link : CVE-2021-22856


JSON object : View

Products Affected

changjia_property_management_system_project

  • changjia_property_management_system
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')