← Back to browse · API

CVE-2021-42369

Severity
CRITICAL
CVSS
9.9
EPSS
0.0105
Risk score
39.97
CISA KEV
No
PoC
No
Published
2021-10-14
Modified
2024-08-04
First seen
2026-08-07
Aliases
EUVD-2021-29340, GHSA-X3C3-8C4J-3CFX
Products
n/a:n/a n/a
Sources
euvd EUVD-2021-29340

Description

Imagicle Application Suite (for Cisco UC) before 2021.Summer.2 allows SQL injection. A low-privileged user could inject a SQL statement through the "Export to CSV" feature of the Contact Manager web GUI.

References