CVE-2021-22851 is a critical SQL Injection vulnerability (CWE-89) affecting HGiga EIP products, specifically hgiga oaklouds_openid. An unauthenticated attacker can exploit this by injecting SQL commands into a specific URL parameter on the document management page, leading to full compromise of the database schema and data. With a CVSS score of 9.8 (CRITICAL), this vulnerability allows for complete confidentiality, integrity, and availability impact with low attack complexity and no user interaction required. While there is no evidence of active exploitation, public exploit code, or significant community discussion, its high severity warrants immediate patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0, < 2.0-54CPE matchmatch criteria | cpe:2.3:a:hgiga:oaklouds_openid:*:*:*:*:*:*:*:* | ||
>= 3.0, < 3.0-54CPE matchmatch criteria | cpe:2.3:a:hgiga:oaklouds_openid:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.