AM Presencia v3.7.3 was discovered to contain a SQL injection vulnerability via the user parameter in the login form.
References
Link | Resource |
---|---|
http://alo.com | Not Applicable |
https://amsystem.es/ | Product |
https://docs.google.com/document/d/1kGzmc6AOCfRzJf9mDz4emkhQj84Y1XemmAMZjYK32-o/edit?usp=sharing | Exploit Third Party Advisory |
https://portalempleado.alosuite.com/home | Not Applicable |
Configurations
History
No history.
Information
Published : 2023-04-13 17:15
Updated : 2023-04-21 04:18
NVD link : CVE-2023-27779
Mitre link : CVE-2023-27779
CVE.ORG link : CVE-2023-27779
JSON object : View
Products Affected
amsystem
- am_presencia
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')