CVE-2021-44793

CVE-2021-44793

Single Connect does not perform an authorization check when using the sc-reports-ui" module. A remote attacker could exploit this vulnerability to access the device configuration page and export the data to an external file. The exploitation of this vulnerability might allow a remote attacker to obtain sensitive information including the database credentials. Since the database runs with high privileges it is possible to execute commands with the attained credentials.

Source: CVE-2021-44793

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다