Beveiligingsadvies

CVE-2019-9846

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2019-03-16 12:00:00
Laatst bijgewerkt 2024-08-04 22:01:55
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

RockOA 1.8.7 allows remote attackers to obtain sensitive information because the webmain/webmainAction.php publictreestore method constructs a SQL WHERE clause unsafely by using the pidfields and idfields parameters, aka background SQL injection.