Ask the Community
Groups
CVE-2020-8427: Unauthenticated SQL Injection - Connect IT Community | Kaseya
<main> <article class="userContent"> <h3 data-id="cve-id"><strong>CVE ID</strong></h3> <p>CVE-2020-8427</p> <h3 data-id="description"><strong>DESCRIPTION</strong></h3> <p>In Unitrends Backup before 10.4.1, an HTTP request parameter was not properly sanitized, allowing for SQL injection that resulted in an authentication bypass.<br><br>This vulnerability was identified and reported by a security researcher, Cale Smith of EasyShell Security.<br><br> </p> <h3 data-id="resolution"><strong>RESOLUTION</strong></h3> <p>Kaseya/Unitrends remediated the vulnerability by changing the execution of a dynamic SQL statement to a parameterized execution. Additionally, standardized input sanitization is being applied to the formally vulnerable parameter. </p> <h1 data-id="n-a"> </h1> <h2 data-id="remediation-timeframe">Remediation Timeframe</h2> Report Received: January 22, 2022<br>Patch Released: February 4, 2020<br>Fix Version: Recovery Series 10.4.1<br><br> <h2 data-id="customer-remediation">Customer Remediation</h2> All customers should upgrade their Unitrends Backup instances to Version 10.4.1 or later.<br> <h3 data-id="link-to-advisories"><strong>LINK TO ADVISORIES</strong></h3> <p></p> <ul></ul><h3 data-id="notes"><strong>NOTES</strong></h3> <p></p> <h2 data-id="related-links">Related Links</h2> <br>Version 10.4.1 Release Notes:<br><a rel="nofollow" href="/home/leaving?allowTrusted=1&target=https%3A%2F%2Funitrends-support.zendesk.com%2Fhc%2Fen-us%2Farticles%2F360013187237">https://unitrends-support.zendesk.com/hc/en-us/articles/360013187237</a><br> </article> </main>