#VU58222 SQL injection in Cisco Common Services Platform Collector - CVE-2021-40129
Published: November 18, 2021
Cisco Common Services Platform Collector
Cisco Systems, Inc
Description
The vulnerability allows a remote user to execute arbitrary SQL queries in database.
The vulnerability exists due to insufficient sanitization of user-supplied data in the configuration dashboard. A remote administrator can send a specially crafted request to the affected application and read restricted information from the CSPC SQL database.