As cited
Copy frozen at (site build).
vulnerabilities
CVE-2017-18362: SQL Injection in ManagedITSync Integration | Huntress
A SQL injection vulnerability, CVE-2017-18362, was identified in the ConnectWise ManagedITSync integration, which synchronizes data between ConnectWise Manage PSA and Kaseya VSA RMM platforms. The flaw was disclosed in late 2017 and could allow attackers to execute arbitrary SQL commands against affected systems.
Why it matters: MSPs and IT service providers using both ConnectWise and Kaseya with the ManagedITSync integration need to verify if they are running patched versions, as SQL injection could expose customer data or enable lateral movement within managed environments.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
CVE-2017-18362: SQL Injection in ManagedITSync Integration | Huntress
A SQL injection vulnerability, CVE-2017-18362, was identified in the ConnectWise ManagedITSync integration, which synchronizes data between ConnectWise Manage PSA and Kaseya VSA RMM platforms. The flaw was disclosed in late 2017 and could allow attackers to execute arbitrary SQL commands against affected systems.
Why it matters: MSPs and IT service providers using both ConnectWise and Kaseya with the ManagedITSync integration need to verify if they are running patched versions, as SQL injection could expose customer data or enable lateral movement within managed environments.
- Source published
- First seen by Cybersecurity Tracker