SQL Injection Vulnerability in Xerox WorkCentre Series
CVE-2018-20770

9.8CRITICAL

Key Information:

Vendor
Xerox
Vendor
CVE Published:
10 February 2019

Summary

A vulnerability has been identified in various models of the Xerox WorkCentre series, where insufficient input validation leads to Blind SQL Injection. This can allow an unauthorized user to execute arbitrary SQL queries through the system's interface, potentially compromising sensitive data and allowing for broader system access. Users are urged to apply the latest firmware updates to mitigate this risk and ensure security compliance.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.