CVE-2018-10997: Etere Etereweb
Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.
Etere EtereWeb before 28.1.20 has a pre-authentication blind SQL injection in the POST parameters txUserName and txPassword.
Affected products
- Etere Etereweb: before 28.1.20 (fixed in 28.1.20)
Published 2018-06-17. Last modified 2026-06-17.