Back to overview

CVE-2020-7356

CRITICAL
10.0
CVSS 3.1
Description
CAYIN xPost suffers from an unauthenticated SQL Injection vulnerability. Input passed via the GET parameter 'wayfinder_seqid' in wayfinder_meeting_input.jsp is not properly sanitized before being returned to the user or used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code and execute SYSTEM commands.

Metadata

CVE ID
CVE-2020-7356
State
PUBLISHED
Assigner
rapid7
Reserved
2020-01-21 00:00 UTC
Published
2020-08-06 15:45 UTC
Last updated
2024-09-17 03:37 UTC
Primary CWE
CWE-89
CWE-89 SQL Injection
Vendor / Product
Cayin Technology / Cayin xPost
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Affected products (1)
VendorProductPlatformVersions
Cayin Technology Cayin xPost 2.5.18103, 2.0, 1.0
Weakness (CWE)
CWESourceDescription
CWE-89 cna CWE-89 SQL Injection
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Back to overview