EFence developed by Thinking Software Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Please update to 1.2.67 DB Ver:57 or later
Workaround
No workaround given by the vendor.
References
History
Mon, 14 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | EFence developed by Thinking Software Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents. | |
| Title | Thinking Software Technology|EFence - SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2026-09-14T11:19:46.131Z
Reserved: 2026-09-11T06:14:53.094Z
Link: CVE-2026-89180
No data.
Status : Received
Published: 2026-09-14T11:17:05.860
Modified: 2026-09-14T11:17:05.860
Link: CVE-2026-89180
No data.
OpenCVE Enrichment
No data.
Weaknesses