SQL injection in Orion Platform - CVE-2021-35234

 

SQL injection in Orion Platform - CVE-2021-35234

Published: December 21, 2021 / Updated: December 27, 2021


Vulnerability identifier: #VU59075
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-35234
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary SQL queries in database.

The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can send a specially crafted request to the affected application and exfiltrate data from the application database. Successful exploitation of the vulnerability may lead to privilege escalation.


Affected software

Orion Platform

How to mitigate CVE-2021-35234

Install update from vendor's website.

Orion Platform - update to 2020.2.6 HF3

External References

Related Security Bulletins