CVE-2021-36722
Summary
| CVE | CVE-2021-36722 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-12-29 15:15:00 UTC |
| Updated | 2022-01-11 14:12:00 UTC |
| Description | Emuse - eServices / eNvoice SQL injection can be used in various ways ranging from bypassing login authentication or dumping the whole database to full RCE on the affected endpoints. The SQLi caused by CWE-209: Generation of Error Message Containig Sensetive Information, showing parts of the aspx code and the webroot location , information an attacker can leverage to further compromise the host. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Emuse - Eservices Envoice Project | Emuse - Eservices / Envoice | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Attention Required! | Cloudflare | CONFIRM | www.gov.il | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Simon Kenin - ClearSky Cyber Security Ltd.
There are currently no legacy QID mappings associated with this CVE.