Title: SQL manipulation via Insecure Design CVE: CVE-2021-44874 Description: The Systeam application is an ERP system that uses a mixed architecture based on SaaS tenant and user management, and on-premise database and web application counterparts. The bi report module exposes direct SQL commands via POST data in order to select data for report generation. A malicious actor can use the bi report endpoint as a direct SQL prompt under the authenticated user. Versão afetada: Versão 2.22.8 build 1724 CORREÇÕES: An updated version has been issued. OWASP TOP 10: A04:2021-Insecure Design CVSS: Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Base Score: 8.8 Credits: Douglas Secco dos Santos DropReal Brasil - Cybersecurtiy & Compliance - www.dropreal.com.br