ID

VAR-202007-1500


TITLE

Hangzhou Yishixing Information Technology Co., Ltd.'s Fanzhi Hotel Human Capital ES Management Platform Group Edition has a SQL injection vulnerability

Trust: 0.6

sources: CNVD: CNVD-2020-33154

DESCRIPTION

Hangzhou Yishixing Information Technology Co., Ltd. is a high-tech enterprise entity specializing in system development, integration and services in the field of card management in the hotel industry personnel logistics and RFID Internet of Things applications. Hangzhou Yishixing Information Technology Co., Ltd. Fanzhi Hotel Human Capital ES Management Platform Group Edition has a SQL injection vulnerability, which can be used by attackers to obtain sensitive database information.

Trust: 0.6

sources: CNVD: CNVD-2020-33154

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-33154

AFFECTED PRODUCTS

vendor:yishixing informationmodel:fanzhi hotel human capital es management platform group edition es300scope: - version: -

Trust: 0.6

vendor:yishixing informationmodel:fanzhi hotel human capital es management platform group edition es600scope: - version: -

Trust: 0.6

vendor:yishixing informationmodel:fanzhi hotel human capital es management platform group edition es2018scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2020-33154

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2020-33154
value: HIGH

Trust: 0.6

CNVD: CNVD-2020-33154
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:C/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2020-33154

PATCH

title:SQL Injection Vulnerability in Fanzhi Hotel Human Capital ES Management Platformurl:https://www.cnvd.org.cn/patchinfo/show/218085

Trust: 0.6

sources: CNVD: CNVD-2020-33154

EXTERNAL IDS

db:CNVDid:CNVD-2020-33154

Trust: 0.6

sources: CNVD: CNVD-2020-33154

SOURCES

db:CNVDid:CNVD-2020-33154

LAST UPDATE DATE

2022-05-04T09:09:00.768000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-33154date:2020-06-17T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-33154date:2020-07-03T00:00:00