go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

HGiga OAKloud Portal - SQL injection -2

TVN ID TVN-202101006
CVE ID CVE-2021-22852
CVSS 8.8 (High)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products OAKSv30 OAKlouds-mol_course_v3 3.0 3.0-124 ~ 3.0-146
OAKSv20 OAKlouds-mol_course_v3 2.0 2.0-124 ~ 2.0-146
Description HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (online registration) to obtain database schema and data.
Solution OAKSv30 OAKlouds-mol_course_v3 3.0 >= 3.0-147
OAKSv20 OAKlouds-mol_course_v3 2.0 >= 2.0-147
Credit Jia-Rong Chen
Public Date 2021-01-19
Top