Cayin xPost SQL Injection
48Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 10epss 14%
from disclosure to weapon0 days
Published on NVDAug 6
metasploitJun 4
exploitation probability
14%top 4% of all CVEs
observed exploitation
nono source reports it
CAYIN xPost suffers from an unauthenticated SQL Injection vulnerability. Input passed via the GET parameter 'wayfinder_seqid' in wayfinder_meeting_input.jsp is not properly sanitized before being returned to the user or used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code and execute SYSTEM commands.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Affected products
Cayin Technology · Cayin xPost