CVE-2021-37749

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
30/08/2021
Last modified:
01/09/2021

Description

MapService.svc in Hexagon GeoMedia WebMap 2020 before Update 2 (aka 16.6.2.66) allows blind SQL Injection via the Id (within sourceItems) parameter to the GetMap method.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hexagongeospatial:geomedia_webmap:*:*:*:*:*:*:*:* 16.6.2.66 (excluding)