Imagicle Application Suite (for Cisco UC) before 2021.Summer.2 allows SQL injection. A low-privileged user could inject a SQL statement through the "Export to CSV" feature of the Contact Manager web GUI.
References
Configurations
History
No history.
Information
Published : 2021-10-14 18:15
Updated : 2023-09-28 14:15
NVD link : CVE-2021-42369
Mitre link : CVE-2021-42369
CVE.ORG link : CVE-2021-42369
JSON object : View
Products Affected
zucchetti
- imagicle_uc_suite
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')