CVE-2021-22852: HGiga OAKloud Portal - SQL injection -2
HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (online registration) to obtain database schema and data.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-22852?
CVE-2021-22852 has a critical severity level due to its potential to expose sensitive database information through SQL injection.
How do I fix CVE-2021-22852?
To fix CVE-2021-22852, ensure that all user inputs are sanitized and validated before being processed by the database.
What systems are affected by CVE-2021-22852?
CVE-2021-22852 affects HGiga OAKlouds OpenID versions between 2.0 and 2.0-54 and versions between 3.0 and 3.0-54.
What kind of attack can exploit CVE-2021-22852?
Attackers can exploit CVE-2021-22852 by injecting malicious SQL commands into the online registration URL parameter.
What information can be compromised by CVE-2021-22852?
CVE-2021-22852 can lead to the exposure of sensitive database schema and data to unauthorized users.