Vulnerability Description
SysAid 20.3.64 b14 is affected by Blind and Stacker SQL injection via AssetManagementChart.jsp (GET computerID), AssetManagementChart.jsp (POST group1), AssetManagementList.jsp (GET computerID or group1), or AssetManagementSummary.jsp (GET group1).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sysaid | Sysaid | 20.3.64 |
Related Weaknesses (CWE)
References
- https://eh337.net/2021/04/10/sysaid-ii/ExploitThird Party Advisory
- https://eh337.net/2021/04/10/sysaid-ii/ExploitThird Party Advisory
FAQ
What is CVE-2021-30486?
CVE-2021-30486 is a vulnerability with a CVSS score of 8.8 (HIGH). SysAid 20.3.64 b14 is affected by Blind and Stacker SQL injection via AssetManagementChart.jsp (GET computerID), AssetManagementChart.jsp (POST group1), AssetManagementList.jsp (GET computerID or grou...
How severe is CVE-2021-30486?
CVE-2021-30486 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-30486?
Check the references section above for vendor advisories and patch information. Affected products include: Sysaid Sysaid.