SQL Injection Vulnerability in Cisco Emergency Responder
CVE-2017-12227
5.4MEDIUM
What is CVE-2017-12227?
A flaw in the SQL database interface for Cisco Emergency Responder allows an authenticated remote attacker to perform a blind SQL injection. This vulnerability arises from inadequate validation of user input in SQL queries, enabling an attacker to bypass security filters. By crafting malicious URLs embedded with SQL statements, the attacker can potentially view or alter database entries, compromising data integrity. This could lead to unauthorized data manipulation and breaches within the affected systems.
Affected Version(s)
Cisco Emergency Responder Cisco Emergency Responder