Lucene search

K
nvd[email protected]NVD:CVE-2021-26795
HistoryNov 14, 2021 - 9:15 p.m.

CVE-2021-26795

2021-11-1421:15:07
CWE-89
web.nvd.nist.gov
5
sql injection
talariax
sendquick alert plus server admin

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

40.3%

A SQL Injection vulnerability in /appliance/shiftmgn.php in TalariaX sendQuick Alert Plus Server Admin 4.3 before 8HF11 allows attackers to obtain sensitive information via a Roster Time to Roster Management.

Affected configurations

Nvd
Node
talariaxsendquick_alert_plus_server_adminRange<4.3
OR
talariaxsendquick_alert_plus_server_adminMatch4.3-
VendorProductVersionCPE
talariaxsendquick_alert_plus_server_admin*cpe:2.3:a:talariax:sendquick_alert_plus_server_admin:*:*:*:*:*:*:*:*
talariaxsendquick_alert_plus_server_admin4.3cpe:2.3:a:talariax:sendquick_alert_plus_server_admin:4.3:-:*:*:*:*:*:*

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

40.3%

Related for NVD:CVE-2021-26795