go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Changing Information Technology Inc. RAVA certificate validation system - SQL Injection

TVN ID TVN-202209012
CVE ID CVE-2022-39056
CVSS 9.8 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products Changing Information Technology Inc. RAVA certificate validation system v3
Description RAVA certificate validation system has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL command to access, modify and delete database.
Solution Contact tech support from Changing
Credit Amos Tsai蔡啟仁 (Acer Cyber Security Inc., ACSI)
Public Date 2022-10-18
Top