Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eliz Software Panel allows Command Line Execution through SQL Injection. This issue affects Panel: before v2.3.24.
The Eliz Software Panel application improperly neutralizes special characters in input data passed to SQL queries, resulting in a classic SQL Injection vulnerability (CWE-89). An attacker with basic system access (PR:L) can craft a malicious SQL query that will be executed by the database engine. The vulnerability enables attack escalation through a system command execution mechanism directly via the SQL engine (Command Line Execution through SQL Injection).
An attacker can gain full control over the system, including reading, modifying and deleting data, as well as executing arbitrary system commands on the server. Due to the high impact on confidentiality, integrity and availability of both the target system and related systems, the breach can lead to complete infrastructure takeover.
Eliz Software Panel must be immediately updated to version v2.3.24 or later. Detailed information is available in the vendor references and USOM message number TR-24-1497.
Eliz Software Panel in versions earlier than v2.3.24.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XElizsoftware Panel
APPElizsoftware< 2.3.24
Related vulnerabilities
Stored XSS w Eliz Software Panel — wstrzyknięcie skryptu po stronie serwera
Przechowywanie haseł w postaci jawnej w Elizsoftware Panel
Reflected XSS w Eliz Software Panel przed wersją v2.3.24