CVE-2018-10997: Etere Etereweb

Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.

Etere EtereWeb before 28.1.20 has a pre-authentication blind SQL injection in the POST parameters txUserName and txPassword.

Affected products

  • Etere Etereweb: before 28.1.20 (fixed in 28.1.20)

Published 2018-06-17. Last modified 2026-06-17.