SQL Injection in Genesys Intelligent Workload Distribution
CVE-2021-40860
7.2HIGH
What is CVE-2021-40860?
A SQL Injection vulnerability exists in the custom filter query component of Genesys Intelligent Workload Distribution prior to version 9.0.013.11. This flaw allows an attacker to manipulate the ql_expression parameter, potentially facilitating the execution of arbitrary SQL queries. Depending on the database permissions and the engine in use, this could lead to unauthorized data extraction or even OS command execution, posing significant security risks to affected systems.
