Back to search
CVE-2019-16917
Published: Oct 17, 2019
Modified: Aug 5, 2024
PUBLISHED
Description
WiKID Enterprise 2FA (two factor authentication) Enterprise Server through 4.2.0-b2047 is vulnerable to SQL injection through the searchDevices.jsp endpoint. The uid and domain parameters are used, unsanitized, in a SQL query constructed in the buildSearchWhereClause function.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20191018 WiKID 2FA Enterprise Server Multiple Issues
mailing-list
x_refsource_FULLDISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now