cve/2023/CVE-2023-21521.md
2024-06-18 02:51:15 +02:00

18 lines
924 B
Markdown
Raw Blame History

This file contains invisible Unicode characters

This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

### [CVE-2023-21521](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21521)
![](https://img.shields.io/static/v1?label=Product&message=AtHoc&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3D%207.15%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
An SQL Injection vulnerability in the Management Console (Operator Audit Trail) of BlackBerry AtHoc version 7.15 could allow an attacker to potentially read sensitive data from the database, modify database data (Insert/Update/Delete), execute administration operations on the database, recover the content of a given file present on the DBMS file system and in some cases issue commands to the operating system.
### POC
#### Reference
- https://support.blackberry.com/kb/articleDetail?articleNumber=000112406
#### Github
No PoCs found on GitHub currently.