An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP POST request and inject SQL statements in the user context of the db owner.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCipplanner Cipace
APPCipplanner< 9.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth BypassSQLi
CWE
Related vulnerabilities
CVE-2020-11598CRITICAL9.8PL ✓same product
CIPAce 9.1 – nieuwierzytelniony upload i RCE przez plik ASHX
CVE-2020-11586CRITICAL9.8PL ✓same product
XXE w CIPPlanner CIPAce — nieautoryzowany dostęp przez złośliwe DTD
CVE-2024-50619HIGH8.8same product
Vulnerabilities in the My Account and User Management components in CIPPlanner CIPAce before 9.17 allows attac...
CVE-2024-50617HIGH7.5same product
Vulnerabilities in the File Download and Get File handler components in CIPPlanner CIPAce before 9.17 allow at...
CVE-2024-50620HIGH8.8same product
Unrestricted Upload of File with Dangerous Type vulnerabilities exist in the rich text editor and document man...