6.5
CVSSv2

CVE-2019-16917

Published: 17/10/2019 Updated: 22/10/2019
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 580
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

WiKID Enterprise 2FA (two factor authentication) Enterprise Server up to and including 4.2.0-b2047 is vulnerable to SQL injection through the searchDevices.jsp endpoint. The uid and domain parameters are used, unsanitized, in a SQL query constructed in the buildSearchWhereClause function.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

wikidsystems two factor authentication enterprise server

Exploits

WiKID Systems 2FA Enterprise Server version 420-b2032 suffers from cross site request forgery, cross site scripting, and remote SQL injection vulnerabilities ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> WiKID 2FA Enterprise Server Multiple Issues <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Aaron Bishop ...