HIGH
RockOA 1.8.7 allows remote attackers to obtain sensitive information because the webmain/webmainAction.php publictreestore method constructs a SQL WHERE clause unsafely by using the pidfields and idfields parameters, aka background SQL injection
Published Mar 16, 2019
8.8
HIGHCVSS 3.0
EPSS 1.68%
Description
Affected products
Remediation
Metrics
References (1)
Change history (0)
No recorded changes yet.