Security Advisory

CVE-2019-9846

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-03-16 12:00:00
Last updated 2024-08-04 22:01:55
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

RockOA 1.8.7 allows remote attackers to obtain sensitive information because the webmain/webmainAction.php publictreestore method constructs a SQL WHERE clause unsafely by using the pidfields and idfields parameters, aka background SQL injection.