Security Advisory

CVE-2018-17796

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-09-30 20:00:00
Last updated 2024-08-05 10:54:10
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

An issue was discovered in MRCMS (aka mushroom) through 3.1.2. The WebParam.java file directly accepts the FIELD_T parameter in a request and uses it as a hash of SQL statements without filtering, resulting in a SQL injection vulnerability in getChannel() in the ChannelService.java file.