1 results (0.004 seconds)

CVSS: 7.2EPSS: 0%CPEs: 1EXPL: 1

08 Dec 2021 — A SQL Injection in the custom filter query component in Genesys intelligent Workload Distribution (IWD) before 9.0.013.11 allows an attacker to execute arbitrary SQL queries via the ql_expression parameter, with which all data in the database can be extracted and OS command execution is possible depending on the permissions and/or database engine. Una inyección SQL en el componente de consulta de filtro personalizado en Genesys intelligent Workload Distribution (IWD) versiones anteriores a 9.0.013.11, permi... • https://docs.genesys.com/Documentation/IWD • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •