Security Advisory
CVE-2018-18982
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
NUUO CMS All versions 3.3 and prior the web server application allows injection of arbitrary SQL characters, which can be used to inject SQL into an executing statement and allow arbitrary code execution.