OSV 1.4.0 · unreviewed · 修改于 2022-04-20 08:01
发布时间
2021-12-23 08:01
GitHub 审查时间
—
NVD 发布时间
2021-12-23 03:15
源文件
advisories/unreviewed/2021/12/GHSA-w84c-gxm3-wgvc/GHSA-w84c-gxm3-wgvc.json
An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at ‘company_filter’ parameter. An attacker can make authenticated HTTP requests to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery.
该公告没有提供结构化的受影响软件包信息。