What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Parcel Panel ParcelPanel.This issue affects ParcelPanel: from n/a through 3.8.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Parcel Panel ParcelPanel.This issue affects ParcelPanel: from n/a through 3.8.1.
Explanation of Vulnerability in Simple Terms
ParcelPanel versions up to 3.8.1 contain a SQL injection vulnerability in a component requiring low-level authentication. An attacker with a valid user account can craft malicious input to execute arbitrary SQL queries, potentially reading sensitive data from the database. The vulnerability affects confidentiality severely and has limited impact on availability. Update to version 4.5.7 or later.
What an attacker can do
Read sensitive data from the database by injecting malicious SQL commands.
Potential impact on your site
Unauthorized database access and exposure of customer or business data stored in ParcelPanel.
Conditions required to exploit
Attacker must have a valid ParcelPanel user account with low-level privileges.
Key dates
External resources
Related vulnerabilities