CVE-2021-43362

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MedData HBYS allows SQL Injection.This issue affects HBYS: from unspecified before 1.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:meddata:hbys:*:*:*:*:*:*:*:*

History

21 Nov 2024, 06:29

Type Values Removed Values Added
CVSS v2 : 7.5
v3 : 9.8
v2 : 7.5
v3 : 9.9
References () https://gist.github.com/Blackh4n/9d8feaf1cfb68f66de17361e85f616d4 - Third Party Advisory () https://gist.github.com/Blackh4n/9d8feaf1cfb68f66de17361e85f616d4 - Third Party Advisory

07 Sep 2023, 08:15

Type Values Removed Values Added
Summary Due to improper sanitization MedData HBYS software suffers from a remote SQL injection vulnerability. An unauthenticated attacker with the web access is able to extract critical information from the system. Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MedData HBYS allows SQL Injection.This issue affects HBYS: from unspecified before 1.1.

03 Sep 2023, 17:15

Type Values Removed Values Added
Summary Due to improper sanitization MedData HBYS software suffers from a remote SQL injection vulnerability. An unauthenticated attacker with the web access is able to extract critical information from the system. Due to improper sanitization MedData HBYS software suffers from a remote SQL injection vulnerability. An unauthenticated attacker with the web access is able to extract critical information from the system.

Information

Published : 2021-11-16 16:15

Updated : 2024-11-21 06:29


NVD link : CVE-2021-43362

Mitre link : CVE-2021-43362

CVE.ORG link : CVE-2021-43362


JSON object : View

Products Affected

meddata

  • hbys
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')