HTTP RULE(RULE ID:338895)

Rule General Information
Release Date: 2025-05-14
Rule Name: Xinet Elegant 6 Asset Lib Web UI 6.1.655 SQL Injection Vulnerability (CVE-2019-19245)
Severity: Critical
CVE ID: CVE-2019-19245
Rule Protection Details
Description: NAPC Xinet Elegant 6 Asset Library 6.1.655 allows Pre-Authentication SQL Injection via the /elegant6/login LoginForm[username] field when double quotes are used.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference: http://hyp3rlinx.altervista.org
https://packetstormsecurity.com/files/155505/Xinet-Elegant-6-Asset-Library-Web-Interface-6.1.655-SQL-Injection.html
http://hyp3rlinx.altervista.org
http://seclists.org/fulldisclosure/2025/Feb/0
Solutions
Please contact the software vendor to update the software patch.