PoC Index

CVE-2019-10123

CRITICAL 9.8EPSS 65.8%

SQL Injection in Advanced InfoData Systems (AIS) ESEL-Server 67 (which is the backend for the AIS logistics mobile app) allows an anonymous attacker to execute arbitrary code in the context of the user of the MSSQL database. The default user for the database is the 'sa' user.

CVSS v3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
65.85% chance of exploitation in the next 30 days, 99th percentile
Published
2019-05-31
Updated
2024-08-04

Metasploit modules (1)

ExploitDB entries (1)

References

Related