Over 10 years we help companies reach their financial and branding goals. Engitech is a values-driven technology agency dedicated.

Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

DATE

29.10.2021

Affected Vendor

Imagicle

Affected Product

Imagicle Application Suite for Cisco UC – https://www.imagicle.com/en/ 

Vulnerable version

2014.Winter.1

Fixed version

2021.Summer.2

Recommendations

Update to Imagicle version 2021.Summer.2

Vulnerability details

Imagicle Application Suite for Cisco UC from version 2014.Winter.1 is vulnerable to SQL injection. A malicious low-privileged authenticated user could inject an SQL statement to the database through the “Export to CSV” of the Contact Manager web GUI. This could lead to disclosure of local administrator’s password, which subsequently could be used to modify the application or make it nonfunctional.

CVE

CVE-2021-42369

Credits

Dawid Czarnecki

Do you think the security of your data might be lacking? Let's find the best approach together.
Once you contact us, we will ask you about the project you want to secure.

NEED A CONSULTATION?