Cisco Unified CM SQL Injection Flaw Let Attackers Execute Crafted SQL Queries

Cisco released fixes for Unified Communications Manager (CM) and Unified Communications Manager Session Management Edition to address high-severity SQL injection vulnerability. “An attacker could exploit this vulnerability by authenticating to the application as a low-privileged user and sending crafted SQL queries to an affected system”, Cisco reports.

Read full article on GBHackers

 


Date:

Categorie(s):