← Back

Grandcom

grandcom

1 CVE • 1 product

Products (1)

Click to collapse
Toggle
Dynweb
dynweb

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Grandcom
1Dynweb
Jun 17, 2026
May 19, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
GRANDCOM DynWEB before 4.2 contains a SQL Injection vulnerability in the admin login interface. A remote unauthenticated attacker can exploit this vulnerability to obtain administrative access to the webpage, access the...Show more
GRANDCOM DynWEB before 4.2 contains a SQL Injection vulnerability in the admin login interface. A remote unauthenticated attacker can exploit this vulnerability to obtain administrative access to the webpage, access the user database, modify web content and upload custom files. The backend login script does not verify and sanitize user-provided strings.Show less