Project Subscriptions
No data.
No advisories yet.
Solution
StoneFly recommends that users upgrade to Storage Concentrator version 8.0.4.29 or later to remediate these vulnerabilities.
Workaround
No workaround given by the vendor.
Wed, 01 Jul 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 30 Jun 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Storage Concentrator (SC & SCVM) is vulnerable to SQL injection through cookie values processed by the login.pl and debug.pl scripts. The cookie value is incorporated directly into database queries without adequate sanitization, allowing an unauthenticated remote attacker to manipulate those queries and extract sensitive information from the underlying database, including session tokens, password hashes, and stored secret keys. | |
| Title | SQL Injection in StoneFly Storage Concentrator | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-07-01T15:35:19.478Z
Reserved: 2026-06-22T20:13:36.520Z
Link: CVE-2026-55721
Updated: 2026-07-01T15:35:16.109Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-01T15:00:06Z