First published: Thu Aug 12 2021(Updated: )
The exporter/Login.aspx login form in the Exporter in Nuance Winscribe Dictation 4.1.0.99 is vulnerable to SQL injection that allows a remote, unauthenticated attacker to read the database (and execute code in some situations) via the txtPassword parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nuance Winscribe Dictation | =4.1.0.99 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2021-37599.
The severity of CVE-2021-37599 is critical with a severity value of 9.8.
The affected software version is Nuance Winscribe Dictation 4.1.0.99.
The CWE ID of this vulnerability is CWE-89.
The vulnerability can be exploited through SQL injection by sending specially crafted input to the txtPassword parameter of the exporter/Login.aspx login form.