First published: Tue Oct 15 2024(Updated: )
WebEIP v3.0 from NewType does not properly validate user input, allowing remote attackers with regular privilege to inject SQL commands to read, modify, and delete data stored in database. The affected product is no longer maintained. It is recommended to upgrade to the new product.
Credit: twcert@cert.org.tw
Affected Software | Affected Version | How to fix |
---|---|---|
NewType WebEIP | =3.0 |
The vendor has stated that WebEIP v3.0 has been released for over 15 years and is no longer supported or maintained. It is recommended to upgrade to the new WebEIP Pro product.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.