CVE-2020-7356
Summary
| CVE | CVE-2020-7356 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-08-06 16:15:00 UTC |
| Updated | 2020-08-12 13:39:00 UTC |
| Description | CAYIN xPost suffers from an unauthenticated SQL Injection vulnerability. Input passed via the GET parameter 'wayfinder_seqid' in wayfinder_meeting_input.jsp is not properly sanitized before being returned to the user or used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code and execute SYSTEM commands. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cayintech | Xpost | 1.0 | All | All | All |
| Application | Cayintech | Xpost | 2.0 | All | All | All |
| Application | Cayintech | Xpost | 2.5.18103 | All | All | All |
| Application | Cayintech | Xpost | 1.0 | All | All | All |
| Application | Cayintech | Xpost | 2.0 | All | All | All |
| Application | Cayintech | Xpost | 2.5.18103 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cayin xPost and CMS exploits by h00die · Pull Request #13607 · rapid7/metasploit-framework · GitHub | MISC | github.com | Patch, Third Party Advisory |
| Zero Science Lab » Cayin Digital Signage System xPost 2.5 Pre-Auth SQLi Remote Code Execution | MISC | www.zeroscience.mk | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: This issue was discovered by Gjoko Krstic of Zero Science Lab.
There are currently no legacy QID mappings associated with this CVE.