Back

CRITICAL

Emuse - eServices / eNvoice SQL injection

Published Dec 29, 2021

Description

Emuse - eServices / eNvoice SQL injection can be used in various ways ranging from bypassing login authentication or dumping the whole database to full RCE on the affected endpoints. The SQLi caused by CWE-209: Generation of Error Message Containig Sensetive Information, showing parts of the aspx code and the webroot location , information an attacker can leverage to further compromise the host.

Affected products

Remediation

Vendor solution

The sql injection vulnerability was fixed by Escaping All User-Supplied Input

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner INCD
Published Dec 29, 2021
Updated Sep 16, 2024
Reserved Jul 12, 2021
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a