CVE-2021-3118

EVOLUCARE ECSIMAGING (aka ECS Imaging) through 6.21.5 has multiple SQL Injection issues in the login form and the password-forgotten form (such as /req_password_user.php?email=). This allows an attacker to steal data in the database and obtain access to the application. (The database component runs as root.) NOTE: This vulnerability only affects products that are no longer supported by the maintainer
References
Link Resource
https://www.exploit-db.com/exploits/49392 Exploit Third Party Advisory VDB Entry
https://www.exploit-db.com/exploits/49392 Exploit Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:medicalexpo:ecs_imaging:*:*:*:*:*:*:*:*

History

21 Nov 2024, 06:20

Type Values Removed Values Added
References () https://www.exploit-db.com/exploits/49392 - Exploit, Third Party Advisory, VDB Entry () https://www.exploit-db.com/exploits/49392 - Exploit, Third Party Advisory, VDB Entry

07 Nov 2023, 03:37

Type Values Removed Values Added
Summary ** UNSUPPORTED WHEN ASSIGNED ** EVOLUCARE ECSIMAGING (aka ECS Imaging) through 6.21.5 has multiple SQL Injection issues in the login form and the password-forgotten form (such as /req_password_user.php?email=). This allows an attacker to steal data in the database and obtain access to the application. (The database component runs as root.) NOTE: This vulnerability only affects products that are no longer supported by the maintainer. EVOLUCARE ECSIMAGING (aka ECS Imaging) through 6.21.5 has multiple SQL Injection issues in the login form and the password-forgotten form (such as /req_password_user.php?email=). This allows an attacker to steal data in the database and obtain access to the application. (The database component runs as root.) NOTE: This vulnerability only affects products that are no longer supported by the maintainer

Information

Published : 2021-01-11 06:15

Updated : 2024-11-21 06:20


NVD link : CVE-2021-3118

Mitre link : CVE-2021-3118

CVE.ORG link : CVE-2021-3118


JSON object : View

Products Affected

medicalexpo

  • ecs_imaging
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')