CVE-2021-33578

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
13/07/2021
Last modified:
15/07/2021

Description

Echo ShareCare 8.15.5 is susceptible to SQL injection vulnerabilities when processing remote input from both authenticated and unauthenticated users, leading to the ability to bypass authentication, exfiltrate Structured Query Language (SQL) records, and manipulate data.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:echobh:sharecare:8.15.5:*:*:*:*:*:*:*