Vulnerability Description
The CGE property management system contains SQL Injection vulnerabilities. Remote attackers can inject SQL commands into the parameters in Cookie and obtain data in the database without privilege.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Changjia Property Management System Project | Changjia Property Management System | 1.00 |
Related Weaknesses (CWE)
References
- https://www.chtsecurity.com/news/fe1e30ef-4dac-4848-a3c9-a7df12672422Third Party Advisory
- https://www.twcert.org.tw/tw/cp-132-4394-76d41-1.htmlThird Party Advisory
- https://www.chtsecurity.com/news/fe1e30ef-4dac-4848-a3c9-a7df12672422Third Party Advisory
- https://www.twcert.org.tw/tw/cp-132-4394-76d41-1.htmlThird Party Advisory
FAQ
What is CVE-2021-22856?
CVE-2021-22856 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The CGE property management system contains SQL Injection vulnerabilities. Remote attackers can inject SQL commands into the parameters in Cookie and obtain data in the database without privilege.
How severe is CVE-2021-22856?
CVE-2021-22856 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-22856?
Check the references section above for vendor advisories and patch information. Affected products include: Changjia Property Management System Project Changjia Property Management System.