SQL Injection Vulnerability in Gallagher Command Centre Software
CVE-2020-16104

8.2HIGH

Key Information:

Vendor

Gallagher

Vendor
CVE Published:
14 December 2020

What is CVE-2020-16104?

An SQL Injection vulnerability exists in the Enterprise Data Interface of Gallagher Command Centre. This flaw allows a remote attacker with 'Edit Enterprise Data Interfaces' privileges to execute arbitrary SQL commands against a third-party database when EDI is configured to import data from this database. This can lead to unauthorized data manipulation or exposure. Affected versions include those prior to 8.30.1236, 8.20.1166, 8.10.1211, 8.00.1228, as well as version 7.90 and earlier.

Affected Version(s)

Command Centre <= 7.90

Command Centre 8.30 < 8.30.1236(MR1)

Command Centre 8.20 < 8.20.1166(MR3)

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.