SQL injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
An attacker with access to the administration console can inject malicious SQL code into vulnerable fields of the web interface. The application does not properly filter input data before passing it to the database engine, allowing the construction and execution of arbitrary SQL queries. This makes it possible to read, modify, or delete data stored in the database, and potentially also execute system operations depending on the database server configuration.
An attacker can read, modify, or delete any data in the application database, leading to complete compromise of system confidentiality and integrity. Depending on the environment configuration, disruption of service availability is also possible.
Ivanti Cloud Services Appliance must be updated to version 5.0.3 or newer in accordance with the manufacturer's recommendations published in the Ivanti security advisory.
Ivanti Cloud Services Appliance (CSA) in all versions prior to 5.0.3
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HIvanti Cloud Services Appliance
APPIvanti< 5.0.3
Related vulnerabilities
OS command injection w Ivanti CSA — RCE dla admina
Authentication bypass w panelu admina Ivanti CSA — pełny dostęp bez logowania
Command injection w konsoli administracyjnej Ivanti CSA umożliwia RCE
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before all...
Default credentials in Ivanti Cloud Services Application before version 5.0.5 allows a local authenticated att...