The users’ data querying function of EIC e-document system does not filter the special characters which resulted in remote attackers can inject SQL syntax and execute arbitrary commands without privilege.
References
Link | Resource |
---|---|
https://www.twcert.org.tw/tw/cp-132-4517-51e25-1.html | Third Party Advisory |
https://gist.github.com/tonykuo76/807c838b75879b0d327782dfcd2c3bea | Third Party Advisory |
https://www.chtsecurity.com/news/c974fd28-c19b-4003-82f3-818904057496 | Third Party Advisory |
Configurations
Information
Published : 2021-03-17 02:15
Updated : 2021-03-23 08:48
NVD link : CVE-2021-22859
Mitre link : CVE-2021-22859
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
eic
- e-document_system