← back
CVE-2021-22851

HGiga OAKloud Portal - SQL injection -1

CVSS 9.8 CRITICALEPSS 1.2%CWE-89
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.8EPSS 1.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
19 Jan 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (document management page) to obtain database schema and data.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →