Vulnerability Description
The login.jsp page of Quicklert for Digium 10.0.0 (1043) is affected by both Blind SQL Injection with Out-of-Band Interaction (DNS) and Blind Time-Based SQL Injections. Exploitation can be used to disclose all data within the database (up to and including the administrative accounts' login IDs and passwords) via the login.jsp uname parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Quicklert | Quicklert | 10.0.0 |
Related Weaknesses (CWE)
References
- https://quicklert.comVendor Advisory
- https://www.assurainc.com/assura-announces-discovery-of-two-vulnerabilities-in-qExploitThird Party Advisory
- https://quicklert.comVendor Advisory
- https://www.assurainc.com/assura-announces-discovery-of-two-vulnerabilities-in-qExploitThird Party Advisory
FAQ
What is CVE-2021-43969?
CVE-2021-43969 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The login.jsp page of Quicklert for Digium 10.0.0 (1043) is affected by both Blind SQL Injection with Out-of-Band Interaction (DNS) and Blind Time-Based SQL Injections. Exploitation can be used to dis...
How severe is CVE-2021-43969?
CVE-2021-43969 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-43969?
Check the references section above for vendor advisories and patch information. Affected products include: Quicklert Quicklert.