AM Presencia v3.7.3 was discovered to contain a SQL injection vulnerability via the user parameter in the login form.
References
Link | Resource |
---|---|
http://alo.com | Not Applicable |
https://amsystem.es/ | Product |
https://docs.google.com/document/d/1kGzmc6AOCfRzJf9mDz4emkhQj84Y1XemmAMZjYK32-o/edit?usp=sharing | Exploit Third Party Advisory |
https://portalempleado.alosuite.com/home | Not Applicable |
http://alo.com | Not Applicable |
https://amsystem.es/ | Product |
https://docs.google.com/document/d/1kGzmc6AOCfRzJf9mDz4emkhQj84Y1XemmAMZjYK32-o/edit?usp=sharing | Exploit Third Party Advisory |
https://portalempleado.alosuite.com/home | Not Applicable |
Configurations
History
21 Nov 2024, 07:53
Type | Values Removed | Values Added |
---|---|---|
References | () http://alo.com - Not Applicable | |
References | () https://amsystem.es/ - Product | |
References | () https://docs.google.com/document/d/1kGzmc6AOCfRzJf9mDz4emkhQj84Y1XemmAMZjYK32-o/edit?usp=sharing - Exploit, Third Party Advisory | |
References | () https://portalempleado.alosuite.com/home - Not Applicable |
21 Apr 2023, 04:18
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-04-13 17:15
Updated : 2024-11-21 07:53
NVD link : CVE-2023-27779
Mitre link : CVE-2023-27779
CVE.ORG link : CVE-2023-27779
JSON object : View
Products Affected
amsystem
- am_presencia
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')