peter bassill · operator
$ cve CVE-2019-10123 JSON

CVE-2019-10123 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 65.9% (pctl 99)

Patch early

A public exploit exists.

Description

SQL Injection in Advanced InfoData Systems (AIS) ESEL-Server 67 (which is the backend for the AIS logistics mobile app) allows an anonymous attacker to execute arbitrary code in the context of the user of the MSSQL database. The default user for the database is the 'sa' user.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS65.85% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2019-05-31
Last modified2026-06-17

Affected (2)

VendorProduct
aisesel-server
aislogistic software

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD