NewType WebEIP v3.0 - SQL injection
Description
NewType WebEIP v3.0 contains a SQL injection vulnerability in input validation, allowing authenticated remote attackers to read, modify, or delete database content.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
NewType WebEIP v3.0 contains a SQL injection vulnerability in input validation, allowing authenticated remote attackers to read, modify, or delete database content.
Vulnerability
NewType WebEIP v3.0 fails to properly validate user input, leading to a SQL injection vulnerability [1][2]. Any remote attacker with regular user privileges can inject arbitrary SQL commands into database queries. The affected product is end-of-life and no longer maintained by the vendor, who recommends upgrading to WebEIP Pro [1][2].
Exploitation
An attacker needs only network access to the WebEIP v3.0 application and a valid low-privileged account. No user interaction or additional privileges are required. By crafting malicious input in a parameter that is passed unsanitized to an SQL query, the attacker can execute arbitrary SQL statements [1][2].
Impact
Successful exploitation allows the attacker to read, modify, and delete any data stored in the underlying database [1][2]. This leads to full compromise of confidentiality, integrity, and availability of the application's data, with a CVSS score of 8.8 (High) [1][2].
Mitigation
NewType WebEIP v3.0 has been discontinued and is no longer supported; no patch will be provided [1][2]. Organizations must upgrade to the vendor's current product, WebEIP Pro, to eliminate the vulnerability [1][2].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2= 3.0+ 1 more
- (no CPE)range: = 3.0
- (no CPE)range: 3.0
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
2- www.twcert.org.tw/en/cp-139-8133-2cc3a-2.htmlmitrethird-party-advisory
- www.twcert.org.tw/tw/cp-132-8132-160bb-1.htmlmitrethird-party-advisory
News mentions
0No linked articles in our index yet.