Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-40861

Опубликовано: 08 дек. 2021
Источник: nvd
CVSS3: 7.2
CVSS2: 6.5
EPSS Низкий

Описание

A SQL Injection in the custom filter query component in Genesys intelligent Workload Distribution (IWD) 9.0.017.07 allows an attacker to execute arbitrary SQL queries via the value attribute, with which all data in the database can be extracted and OS command execution is possible depending on the permissions and/or database engine.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:genesys:intelligent_workload_distribution_manager:*:*:*:*:*:*:*:*
Версия от 9.0.013.11 (включая) до 9.0.017.07 (исключая)

EPSS

Процентиль: 84%
0.02164
Низкий

7.2 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-89

Связанные уязвимости

github
около 4 лет назад

A SQL Injection in the custom filter query component in Genesys intelligent Workload Distribution (IWD) 9.0.017.07 allows an attacker to execute arbitrary SQL queries via the value attribute, with which all data in the database can be extracted and OS command execution is possible depending on the permissions and/or database engine.

EPSS

Процентиль: 84%
0.02164
Низкий

7.2 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-89