go to Content

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center



Soar Cloud System Co., Ltd. HR Portal - SQL Injection

TVN ID TVN-202101008
CVE ID CVE-2021-22854
CVSS 7.5 (High)
Affected Products Soar Cloud System Co., Ltd. HR Portal version 7.3.2020.1013
Description The HR Portal of Soar Cloud System fails to filter specific parameters. Remote attackers can inject SQL syntax and obtain all data in the database without privilege.
Solution Update to version 7.3.2020.1110
Credit TsungShu Chiu
Public Date 2021-02-17