CVE Published: 17/02/2021 |
CVE Updated: 17/09/2024 |
CVE Year: 2021 Source: twcert |
Vendor: ChanGate EnterPrise Co., Ltd |
Product: property management system Status : PUBLISHED
CVE-2021-22856 Description
The CGE property management system contains SQL Injection vulnerabilities. Remote attackers can inject SQL commands into the parameters in Cookie and obtain data in the database without privilege.
Metrics
CVSS Version: 3.1 |
Base Score: 9.8 CRITICAL Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H