SQL Injection Vulnerability in RockOA Product by RockOA
CVE-2019-9846

8.8HIGH

Key Information:

Vendor

Rockoa

Status
Vendor
CVE Published:
28 June 2019

What is CVE-2019-9846?

RockOA version 1.8.7 is susceptible to SQL injection through its webmain/webmainAction.php's publictreestore method. This vulnerability arises due to improper construction of SQL WHERE clauses, allowing remote attackers to manipulate SQL queries using the pidfields and idfields parameters. Consequently, attackers may gain unauthorized access to sensitive information stored in the database.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2019-9846 : SQL Injection Vulnerability in RockOA Product by RockOA