RULE(RULE ID:337885)

Rule General Information
Release Date: 2024-04-02
Rule Name: Realor GWT System SQL Injection Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Sql injection vulnerability exists in the Realor GWT system 7.0.2.1 and previous versions. The vulnerability is due to the fact that the Realor GWT system does not filter the incoming data of the user, and directly concatenates the user input directly into the sql statement for execution. A malicious attacker without authentication successfully uses this vulnerability to obtain sensitive information in the database. Or write the webshell backdoor, so as to execute arbitrary code on the target server to obtain control rights of the target server.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.