PT-2022-11740 · Unknown · Dhbw Fallstudie

CVE-2021-4290

·

Published

2022-12-27

·

Updated

2024-05-17

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DHBW Fallstudie (affected versions not specified)
Description A critical issue was found in DHBW Fallstudie, affecting an unknown functionality of the file app/config/passport.js in the Login component. The manipulation of the id/email argument leads to SQL injection.
Recommendations To fix this issue, it is recommended to apply a patch with the name 5c13c6a972ef4c07c5f35b417916e0598af9e123. As a temporary workaround, consider restricting access to the id/email argument in the affected Login component to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-4290

Affected Products

Dhbw Fallstudie