Loading HuntDB...

[CRITICAL] Sql Injection on http://axa.dxi.eu

Critical
8
8x8
Submitted None

Team Summary

Official summary from 8x8

One of the micro service endpoints of the ContactNow application constructed a SQL query utilizing user provided parameters without utilizing a proper prepared statement.

Reported by madrobot

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

SQL Injection