NeDi 1.9C allows an authenticated user to perform a SQL Injection in the Monitoring History function on the endpoint /Monitoring-History.php via the det HTTP GET parameter. This allows an attacker to access all the data in the database and obtain access to the NeDi application.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2021-02-12T20:35:48
Updated: 2024-08-03T20:33:40.787Z
Reserved: 2021-02-05T00:00:00
Link: CVE-2021-26751
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-02-12T21:15:12.900
Modified: 2024-11-21T05:56:47.797
Link: CVE-2021-26751
Redhat
No data.