CVE-2019-10123
Last modified
CVE-2019-10123 is a vulnerability of currently unknown severity. SQL Injection in Advanced InfoData Systems (AIS) ESEL-Server 67 (which is the backend for the AIS logistics mobile app) allows an anonymous attacker to execute arbitrary code in the context of the user of the MSSQL database. The default user for the database is the 'sa' user.. EPSS estimates a 65.85% chance of exploitation in the next 30 days.
Description
SQL Injection in Advanced InfoData Systems (AIS) ESEL-Server 67 (which is the backend for the AIS logistics mobile app) allows an anonymous attacker to execute arbitrary code in the context of the user of the MSSQL database. The default user for the database is the 'sa' user.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ais | Logistic Software | <= 67 |
References
- https://github.com/rapid7/metasploit-framework/pull/11641/Exploit, Third Party Advisory
- https://www.ais.deVendor Advisory
- https://github.com/rapid7/metasploit-framework/pull/11641/Exploit, Third Party Advisory
- https://www.ais.deVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-10123?
How severe is CVE-2019-10123?
How do I fix CVE-2019-10123?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-10118Snipe-IT before 4.6.14 has XSS, as demonstrated by log_meta …
- CVE-2019-10119eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices b…
- CVE-2019-1012An information disclosure vulnerability exists when the Wind…4.7
- CVE-2019-10120On eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 device…
- CVE-2019-10121eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices b…
- CVE-2019-10122eQ-3 HomeMatic CCU2 devices before 2.41.9 and CCU3 devices b…
- CVE-2019-10124Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-10125An issue was discovered in aio_poll() in fs/aio.c in the Lin…9.8
- CVE-2019-10126A flaw was found in the Linux kernel. A heap based buffer ov…9.8
- CVE-2019-10127A vulnerability was found in postgresql versions 11.x prior …8.8
- CVE-2019-10128A vulnerability was found in postgresql versions 11.x prior …7.8
- CVE-2019-10129A vulnerability was found in postgresql versions 11.x prior …6.5
Are you affected by CVE-2019-10123?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
