SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-43969

The login.jsp page of Quicklert for Digium 10.0.0 (1043) is affected by both Blind SQL Injection with Out-of-Band Interaction (DNS) and Blind Time-Based SQL Injections.

MEDIUM 6.5EPSS 1.51%

Does this matter?

Lower severity and a low EPSS score (1.51%). Track it; it rarely justifies an emergency change on its own.

Description

The login.jsp page of Quicklert for Digium 10.0.0 (1043) is affected by both Blind SQL Injection with Out-of-Band Interaction (DNS) and Blind Time-Based SQL Injections. Exploitation can be used to disclose all data within the database (up to and including the administrative accounts' login IDs and passwords) via the login.jsp uname parameter.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
1.51% probability · 73th percentile
CISA KEV
Not listed
Weakness
CWE-89
Affected
quicklert/quicklert
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.