Vulnerability Details CVE-2021-32953
An attacker could utilize SQL commands to create a new user MDT AutoSave versions prior to v6.02.06 and update the user’s permissions, granting the attacker the ability to login.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 43.8%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2021-32953
-
cpe:2.3:a:auvesy-mdt:autosave:*
-
cpe:2.3:a:auvesy-mdt:autosave_for_system_platform:*
-
cpe:2.3:a:auvesy-mdt:autosave_for_system_platform:5.00