Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-6316 | By using an Automate API in ConnectWise Automate before 2020.5.178, a remote authenticated user could execute commands and/or modifications within an individual Automate instance by triggering an SQL injection vulnerability in /LabTech/agent.aspx. This affects versions before 2019.12.337, 2020 before 2020.1.53, 2020.2 before 2020.2.85, 2020.3 before 2020.3.114, 2020.4 before 2020.4.143, and 2020.5 before 2020.5.178. |
| Link | Providers |
|---|---|
| https://www.connectwise.com/company/trust#tab1 |
|
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T12:39:36.131Z
Reserved: 2020-06-15T00:00:00.000Z
Link: CVE-2020-14159
No data.
Status : Modified
Published: 2020-06-15T19:15:10.167
Modified: 2026-06-17T02:54:18.863
Link: CVE-2020-14159
No data.
OpenCVE Enrichment
No data.
-
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
EUVD