CVE-2020-7356
Cayin xPost SQL Injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
CAYIN xPost suffers from an unauthenticated SQL Injection vulnerability. Input passed via the GET parameter 'wayfinder_seqid' in wayfinder_meeting_input.jsp is not properly sanitized before being returned to the user or used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code and execute SYSTEM commands.
CAYIN xPost sufre una vulnerabilidad de inyección SQL no autenticada. La entrada pasada por medio del parámetro GET "wayfinder_seqid" en el archivo wayfinder_meeting_input.jsp no es saneada correctamente antes de ser devuelta al usuario o usada en consultas SQL. Esta puede ser explotada para manipular consultas SQL mediante la inyección de código SQL arbitrario y ejecutar comandos SYSTEM
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-01-21 CVE Reserved
- 2020-06-18 CVE Published
- 2024-09-17 CVE Updated
- 2024-09-17 First Exploit
- 2024-10-01 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5571.php | 2024-09-17 |
URL | Date | SRC |
---|---|---|
https://github.com/rapid7/metasploit-framework/pull/13607 | 2020-08-12 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cayintech Search vendor "Cayintech" | Xpost Search vendor "Cayintech" for product "Xpost" | 1.0 Search vendor "Cayintech" for product "Xpost" and version "1.0" | - |
Affected
| ||||||
Cayintech Search vendor "Cayintech" | Xpost Search vendor "Cayintech" for product "Xpost" | 2.0 Search vendor "Cayintech" for product "Xpost" and version "2.0" | - |
Affected
| ||||||
Cayintech Search vendor "Cayintech" | Xpost Search vendor "Cayintech" for product "Xpost" | 2.5.18103 Search vendor "Cayintech" for product "Xpost" and version "2.5.18103" | - |
Affected
|