CVE-2021-42369
CRITICALZucchetti Imagicle UC Suite < 2021.summer.2 - SQL Injection
Title source: ruleDescription
Imagicle Application Suite (for Cisco UC) before 2021.Summer.2 allows SQL injection. A low-privileged user could inject a SQL statement through the "Export to CSV" feature of the Contact Manager web GUI.
References (3)
Core 3
Core References
Various Sources
https://zigrin.com/advisories/imagicle-sql-injection-vulnerability-in-contacts-csv-export/
Third Party Advisory
https://github.com/dawid-czarnecki/public-vulnerabilities/tree/master/Imagicle/CVE
Vendor Advisory
https://www.imagicle.com/en/resources/download/
Scores
CVSS v3
9.9
EPSS
0.0042
EPSS Percentile
62.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Details
CWE
CWE-89
Status
published
Products (1)
zucchetti/imagicle_uc_suite
< 2021.summer.2
Published
Oct 14, 2021
Tracked Since
Feb 18, 2026