Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Cisco Smart Software Manager On-Prem SQL Injection Vulnerability
Vulnerability Description
A vulnerability in the web-based management interface of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the web-based management interface inadequately validates user input. An attacker could exploit this vulnerability by authenticating to the application as a low-privileged user and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to read sensitive data on the underlying database.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
Cisco Smart Software Manager On-Prem SQL注入漏洞
Vulnerability Description
Cisco Smart Software Manager On-Prem(SSM On-Prem)是美国思科(Cisco)公司的一款用于Cisco产品许可证管理的组件。 Cisco Smart Software Manager On-Prem (SSM On-Prem) 存在安全漏洞,该漏洞源于基于 Web 的管理界面中的漏洞。经过身份验证的远程攻击者利用该漏洞可以对受影响的系统进行 SQL 注入攻击。
CVSS Information
N/A
Vulnerability Type
N/A