ID

VAR-202104-2061


TITLE

SQL injection vulnerability exists in the water rights trading system (CNVD-2021-18291)

Trust: 0.6

sources: CNVD: CNVD-2021-18291

DESCRIPTION

Tangshan Liulin Automation Equipment Co., Ltd. is a high-tech enterprise specializing in the research and development, production, sales and system engineering technical services of the security communication terminal and smart application platform software of the Internet of Things. There is a SQL injection vulnerability in the water rights trading system. Attackers can use the vulnerability to obtain sensitive information in the database.

Trust: 0.6

sources: CNVD: CNVD-2021-18291

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2021-18291

AFFECTED PRODUCTS

vendor:liulin automation equipmentmodel:water rights trading systemscope:eqversion:2017

Trust: 0.6

sources: CNVD: CNVD-2021-18291

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2021-18291
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2021-18291
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:L/AU:S/C:C/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2021-18291

EXTERNAL IDS

db:CNVDid:CNVD-2021-18291

Trust: 0.6

sources: CNVD: CNVD-2021-18291

SOURCES

db:CNVDid:CNVD-2021-18291

LAST UPDATE DATE

2022-05-04T09:37:47.548000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2021-18291date:2021-03-22T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2021-18291date:2021-04-12T00:00:00