CVE-2020-25253: SQL Injection
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It allows SQL injection, as demonstrated by the TableName, ColumnName, Name, UserId, or Password parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-25253?
CVE-2020-25253 is classified as a critical severity vulnerability due to its potential for SQL injection.
How do I fix CVE-2020-25253?
To fix CVE-2020-25253, upgrade Hyland OnBase to a version above 16.0.2.83, 17.0.2.109, 18.0.0.37, 19.8.16.1000, or 20.3.10.1000.
What software versions are affected by CVE-2020-25253?
CVE-2020-25253 affects Hyland OnBase versions 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below, and 20.3.10.1000 and below.
What types of injections does CVE-2020-25253 allow?
CVE-2020-25253 allows SQL injection through parameters such as TableName, ColumnName, Name, UserId, or Password.
How can I prevent vulnerabilities like CVE-2020-25253?
To prevent vulnerabilities like CVE-2020-25253, implement secure coding practices such as parameterized queries and regular software updates.