Home
CRITICAL: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
CIGESv2
affected
Description
SQL injection vulnerability in the CIGESv2 system, through /ajaxConfigTotem.php, in the 'id' parameter. The exploitation of this vulnerability could allow a remote user to retrieve all data stored in the database by sending a specially crafted SQL query.
Problem types
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
CIGESv2
Credits
Óscar Atienza
References
www.incibe.es/...iso/multiple-vulnerabilities-cigesv2-system
www.incibe.es/...iso/multiple-vulnerabilities-cigesv2-system