Overview
Avanset Visual CertExam Manager version 3.3 and below contain a SQL injection vulnerability.
Description
CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Avanset Visual CertExam Manager version 3.3 and below contain a SQL injection vulnerability due to the application failing to validate user input variables. It has been reported that the fields "Title", "File name", and "Candidate Name" are all vulnerable to SQL injection. |
Impact
An authenticated attacker can read or modify data in the application database. |
Solution
We are currently unaware of a practical solution to this problem. |
Restrict Access |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 6.5 | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Temporal | 5.6 | E:POC/RL:U/RC:UR |
Environmental | 1.4 | CDP:N/TD:L/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to security researcher Mr. Aung Khant (aungkhant0911@gmail.com) for reporting this vulnerability.
This document was written by Michael Orlando.
Other Information
CVE IDs: | CVE-2013-7175 |
Date Public: | 2014-01-17 |
Date First Published: | 2014-01-23 |
Date Last Updated: | 2014-07-24 22:11 UTC |
Document Revision: | 13 |