CVE-2021-43361

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MedData HBYS allows SQL Injection.This issue affects HBYS: from unspecified before 1.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:meddata:hbys:*:*:*:*:*:*:*:*

History

21 Nov 2024, 06:29

Type Values Removed Values Added
References () https://github.com/bartutku/CVE-2021-43361/blob/main/CVE-2021-43361.txt - Third Party Advisory () https://github.com/bartutku/CVE-2021-43361/blob/main/CVE-2021-43361.txt - Third Party Advisory
CVSS v2 : 7.5
v3 : 9.8
v2 : 7.5
v3 : 9.9

07 Sep 2023, 08:15

Type Values Removed Values Added
Summary Due to improper sanitization MedData HBYS software suffers from a remote SQL injection vulnerability. An unauthenticated attacker with the web access is able to extract critical information from the system. Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MedData HBYS allows SQL Injection.This issue affects HBYS: from unspecified before 1.1.

03 Sep 2023, 17:15

Type Values Removed Values Added
Summary Due to improper sanitization MedData HBYS software suffers from a remote SQL injection vulnerability. An unauthenticated attacker with the web access is able to extract critical information from the system. Due to improper sanitization MedData HBYS software suffers from a remote SQL injection vulnerability. An unauthenticated attacker with the web access is able to extract critical information from the system.

Information

Published : 2021-11-16 16:15

Updated : 2024-11-21 06:29


NVD link : CVE-2021-43361

Mitre link : CVE-2021-43361

CVE.ORG link : CVE-2021-43361


JSON object : View

Products Affected

meddata

  • hbys
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')