Vianeos OctoPUS 5 - 'login_user' SQLi
Vulnerability Description
Vianeos OctoPUS 5 contains a time-based blind SQL injection vulnerability in the 'login_user' parameter during authentication requests. Attackers can exploit this vulnerability by crafting malicious POST requests with specially constructed SQL payloads that trigger database sleep functions to extract information.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-47801
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Audencia Business SCHOOL
Affected Vendor
Vianeos
View all reports →