First published: Thu Oct 31 2019(Updated: )
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. Lack of sanitization of user-supplied input cause SQL injection vulnerabilities. An attacker can leverage these vulnerabilities to disclose information.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech WISE-PaaS/RMM | ||
Advantech WISE-PaaS/RMM | <=3.3.29 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-18229 is rated as a medium severity vulnerability due to its potential for SQL injection.
To fix CVE-2019-18229, upgrade to a version of Advantech WISE-PaaS/RMM later than 3.3.29 that addresses this vulnerability.
CVE-2019-18229 allows remote attackers to execute SQL injection, potentially leading to sensitive information disclosure.
Any user of Advantech WISE-PaaS/RMM versions 3.3.29 and prior is affected by CVE-2019-18229.
Yes, CVE-2019-18229 can be exploited remotely by attackers if the user-supplied input is not properly sanitized.