Vulnerability Description
An issue was discovered in Aptean Product Configurator 4.61.0000 on Windows. A Time based SQL injection affects the nameTxt parameter on the main login page (aka cse?cmd=LOGIN). This can be exploited directly, and remotely.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Aptean | Product Configurator | 4.61.0000 |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://www.aptean.comVendor Advisory
- https://www.logicallysecure.com/blog/sql-injection-in-aptean/ExploitThird Party Advisory
- https://www.aptean.comVendor Advisory
- https://www.logicallysecure.com/blog/sql-injection-in-aptean/ExploitThird Party Advisory
FAQ
What is CVE-2020-26944?
CVE-2020-26944 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered in Aptean Product Configurator 4.61.0000 on Windows. A Time based SQL injection affects the nameTxt parameter on the main login page (aka cse?cmd=LOGIN). This can be exploited ...
How severe is CVE-2020-26944?
CVE-2020-26944 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-26944?
Check the references section above for vendor advisories and patch information. Affected products include: Aptean Product Configurator, Microsoft Windows.