CVE-2014-4858: Sabreairlinesolutions Crew Management
High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.
Multiple SQL injection vulnerabilities in CWPLogin.aspx in Sabre AirCentre Crew products 2010.2.12.20008 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field.
Affected products
- Sabreairlinesolutions Crew Management: up to and including 2010.2.12.20008
- Sabreairlinesolutions Crew Operations: up to and including 2010.2.12.20008
- Sabreairlinesolutions Crew Planning: up to and including 2010.2.12.20008
- Sabreairlinesolutions Crew Services: up to and including 2010.2.12.20008
- Sabreairlinesolutions Crew Training: up to and including 2010.2.12.20008
Published 2014-07-26. Last modified 2026-06-17.