CVE-2021-42369

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
14/10/2021
Last modified:
28/09/2023

Description

Imagicle Application Suite (for Cisco UC) before 2021.Summer.2 allows SQL injection. A low-privileged user could inject a SQL statement through the "Export to CSV" feature of the Contact Manager web GUI.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zucchetti:imagicle_uc_suite:*:*:*:*:*:*:*:* 2021.summer.2 (excluding)