go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

ITPison OMICARD EDM - SQL Injection

TVN ID TVN-202206010
CVE ID CVE-2022-32964
CVSS 9.8 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products ITPison OMICARD EDM v5.8~v6.0
Description OMICARD EDM’s API function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL commands to access, modify, delete database or disrupt service.
Solution Contact tech support from ITPison.
Credit Xin-Yue, Song (CHT Security)
Public Date 2022-08-04
Top