Fiche vulnérabilité
CVE-2021-22851 : faille critique hgiga oaklouds openid (CVSS 9.8)
Description
HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (document management page) to obtain database schema and data.
En bref
- Sévérité
- Critique (CVSS 9.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 19 janv. 2021
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- hgiga oaklouds openid