SQL Injection Vulnerability in Gallagher Command Centre Software
CVE-2020-16104
8.2HIGH
What is CVE-2020-16104?
An SQL Injection vulnerability exists in the Enterprise Data Interface of Gallagher Command Centre. This flaw allows a remote attacker with 'Edit Enterprise Data Interfaces' privileges to execute arbitrary SQL commands against a third-party database when EDI is configured to import data from this database. This can lead to unauthorized data manipulation or exposure. Affected versions include those prior to 8.30.1236, 8.20.1166, 8.10.1211, 8.00.1228, as well as version 7.90 and earlier.
Affected Version(s)
Command Centre <= 7.90
Command Centre 8.30 < 8.30.1236(MR1)
Command Centre 8.20 < 8.20.1166(MR3)
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
