6.5
CVSSv3

CVE-2019-15995

Published: 26/11/2019 Updated: 09/12/2019
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 5.2 | Exploitability Score: 1.2
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:P

Vulnerability Summary

A vulnerability in the web UI of Cisco DNA Spaces: Connector could allow an authenticated, remote malicious user to execute arbitrary SQL queries. The vulnerability exists because the web UI does not properly validate user-supplied input. An attacker could exploit this vulnerability by entering malicious SQL statements in an affected field in the web UI. A successful exploit could allow the malicious user to remove the SQL database, which would require the reinstallation of the Connector VM.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco dna spaces\\ _connector

Vendor Advisories

A vulnerability in the web UI of Cisco DNA Spaces: Connector could allow an authenticated, remote attacker to execute arbitrary SQL queries The vulnerability exists because the web UI does not properly validate user-supplied input An attacker could exploit this vulnerability by entering malicious SQL statements in an affected field in the web UI ...