Advantech WebAccess/VPN SQL Injection Vulnerability in AjaxStandaloneVpnClientsController
Vulnerability
A SQL injection vulnerability has been identified in Advantech WebAccess/VPN versions prior to 1.1.5. The issue resides in the AjaxStandaloneVpnClientsController.ajaxAction() method, where an authenticated low-privileged observer user can inject SQL through datatable search parameters. This injection could lead to unauthorized disclosure of database information.
Impact
Exploitation of this vulnerability allows for SQL injection, where an attacker could manipulate SQL queries to access, modify, or delete database information. In this case, the vulnerability could be exploited to disclose sensitive database information.
Remediation
Users are advised to upgrade to Advantech WebAccess/VPN version 1.1.5.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
