CVE-2021-32582
17.06.2021, 12:15
An issue was discovered in ConnectWise Automate before 2021.5. A blind SQL injection vulnerability exists in core agent inventory communication that can enable an attacker to extract database information or administrative credentials from an instance via crafted monitor status responses.
| Vendor | Product | Version |
|---|---|---|
| connectwise | connectwise_automate | 𝑥 < 2021.5 |
𝑥
= Vulnerable software versions
References