← All CVEs

CVE-2020-7356

critical · 10

CAYIN xPost suffers from an unauthenticated SQL Injection vulnerability. Input passed via the GET parameter 'wayfinder_seqid' in wayfinder_meeting_input.jsp is not properly sanitized before being returned to the user or used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code and execute SYSTEM commands.

10
CVSS
14.0%
EPSS (exploit prob.)
96th
EPSS percentile
2020-08-06
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Weaknesses

CWE-89

Affected products

VendorProductAffected versions
cayintechxpost1.0
cayintechxpost2.0
cayintechxpost2.5.18103

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2020-7356