← Back to browse · API

CVE-2020-7356

Severity
CRITICAL
CVSS
10.0
EPSS
0.14014
Risk score
44.9
CISA KEV
No
PoC
No
Published
2020-08-06
Modified
2024-09-17
First seen
2026-08-07
Aliases
EUVD-2020-28483, GHSA-RX8Q-GF7P-3FVP
Products
Cayin Technology:Cayin xPost 1.0, Cayin Technology:Cayin xPost 2.0, Cayin Technology:Cayin xPost 2.5.18103
Sources
euvd EUVD-2020-28483

Description

CAYIN xPost suffers from an unauthenticated SQL Injection vulnerability. Input passed via the GET parameter 'wayfinder_seqid' in wayfinder_meeting_input.jsp is not properly sanitized before being returned to the user or used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code and execute SYSTEM commands.

References