First published: Thu Jul 22 2021(Updated: )
SysAid 20.3.64 b14 is affected by Blind and Stacker SQL injection via AssetManagementChart.jsp (GET computerID), AssetManagementChart.jsp (POST group1), AssetManagementList.jsp (GET computerID or group1), or AssetManagementSummary.jsp (GET group1).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sysaid On-Premises | =20.3.64-b14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-30486 is a vulnerability in SysAid 20.3.64 b14 that allows Blind and Stacker SQL injection via multiple endpoints.
CVE-2021-30486 affects SysAid 20.3.64 b14 through vulnerabilities in AssetManagementChart.jsp (GET computerID), AssetManagementChart.jsp (POST group1), AssetManagementList.jsp (GET computerID or group1), or AssetManagementSummary.jsp (GET group1).
CVE-2021-30486 has a severity rating of 8.8 (high).
To fix CVE-2021-30486 in SysAid, ensure you are using the latest version of SysAid software and follow the patching instructions provided by SysAid.
You can find more information about CVE-2021-30486 at the following reference: https://eh337.net/2021/04/10/sysaid-ii/