SQL injection vulnerability in AES Multimedia's Gestnet v1.07. This vulnerability allows an attacker to retrieve, create, update and delete databases via the ‘fk_remoto_central’ parameter on the ‘/webservices/articles.php’ endpoint.
The vulnerability occurs in the 'fk_remoto_central' parameter handled by the '/webservices/articles.php' endpoint. The application does not filter or parameterize user-supplied input data, allowing an attacker to inject malicious SQL queries directly into the database engine. The attack requires no authentication or user interaction, and can be carried out remotely over the network.
An attacker can read, create, modify, and delete any data stored in the application's database. In practice, this means the possibility of stealing sensitive information, data manipulation, or complete destruction of database contents.
Apply patches available from the manufacturer according to the references. Additional temporary measures may include restricting network access to the '/webservices/articles.php' endpoint exclusively to trusted IP addresses and implementing Web Application Firewall (WAF) rules blocking typical SQL injection patterns.
AES Multimedia Gestnet version 1.07
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X