CVE-2020-26805

In Sentrifugo 3.2, admin can edit employee's informations via this endpoint --> /sentrifugo/index.php/empadditionaldetails/edit/userid/2. In this POST request, "employeeNumId" parameter is affected by SQLi vulnerability. Attacker can inject SQL commands into query, read data from database or write data into the database.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:sapplica:sentrifugo:3.2:*:*:*:*:*:*:*

Information

Published : 2020-11-12 11:15

Updated : 2020-11-17 07:43


NVD link : CVE-2020-26805

Mitre link : CVE-2020-26805


JSON object : View

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Advertisement

dedicated server usa

Products Affected

sapplica

  • sentrifugo