SQL Injection Vulnerability in Odyssey by Yandex Affecting Client Authentication
CVE-2021-43766
8.1HIGH
What is CVE-2021-43766?
The Odyssey software by Yandex is vulnerable to a security flaw where it transmits unencrypted bytes from the client to the server during initial connection establishment. When configured to utilize the certificate Common Name for client authentication, a man-in-the-middle attacker can exploit this vulnerability to inject arbitrary SQL queries, potentially leading to unauthorized access or manipulation of database information. Despite employing SSL certificate verification and encryption, this issue poses significant risks to data integrity and confidentiality.
Affected Version(s)
Odyssey Odyssey 1.1