SQL Injection Vulnerability in eBrigade Software
CVE-2019-16745

8.8HIGH

Key Information:

Vendor

Ebrigade

Status
Vendor
CVE Published:
30 September 2019

What is CVE-2019-16745?

eBrigade versions prior to 5.0 are susceptible to a SQL injection vulnerability in the evenement_choice.php file, specifically related to the chxCal parameter. This flaw allows an attacker to execute arbitrary SQL commands, which could lead to unauthorized access to sensitive data, modification of database contents, or even complete control over the database. It is crucial for users of eBrigade to update to the latest version to mitigate this risk and enhance their security posture.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.