CVE-2021-41932

A blind SQL injection vulnerability in search form in TeamMate+ Audit version 28.0.19.0 allows any authenticated user to create malicious SQL injections, which can result in complete database compromise, gaining information about other users, unauthorized access to audit data etc.
References
Link Resource
https://mjilek.cz/blog/CVE-2021-41932/ Exploit Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:wolterskluwer:teammate\+_audit:28.0.19.0:*:*:*:*:*:*:*

Information

Published : 2022-06-06 08:15

Updated : 2022-06-13 10:43


NVD link : CVE-2021-41932

Mitre link : CVE-2021-41932


JSON object : View

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Advertisement

dedicated server usa

Products Affected

wolterskluwer

  • teammate\+_audit