SQL Injection in SicommNet BASEC SaaS Enabling Unauthenticated Authentication Bypass
An SQL Injection vulnerability exists in SicommNet BASEC SaaS Service login page that enables an unauthenticated remote attacker to bypass authentication and execute arbitrary SQL commands. This security issue has been confirmed for BASEC versions from 14 Dec 2021 onwards, and is likely to have been present in earlier versions as well. As of the current CVE record date, no patch has been released to address this vulnerability.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
sicommnet basec |