Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-32c2-v3m4-9q5j

Опубликовано: 11 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

Network Olympus version 1.8.0 allows an authenticated admin user to inject SQL queries in '/api/eventinstance' via the 'sqlparameter' JSON parameter. It is also possible to achieve remote code execution in the default installation (PostgreSQL) by exploiting this issue.

Network Olympus version 1.8.0 allows an authenticated admin user to inject SQL queries in '/api/eventinstance' via the 'sqlparameter' JSON parameter. It is also possible to achieve remote code execution in the default installation (PostgreSQL) by exploiting this issue.

EPSS

Процентиль: 89%
0.04433
Низкий

7.2 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 7.2
nvd
почти 4 года назад

Network Olympus version 1.8.0 allows an authenticated admin user to inject SQL queries in '/api/eventinstance' via the 'sqlparameter' JSON parameter. It is also possible to achieve remote code execution in the default installation (PostgreSQL) by exploiting this issue.

EPSS

Процентиль: 89%
0.04433
Низкий

7.2 High

CVSS3

Дефекты

CWE-89