SQL Injection Vulnerability in RockOA Product by RockOA
CVE-2019-9846
8.8HIGH
What is CVE-2019-9846?
RockOA version 1.8.7 is susceptible to SQL injection through its webmain/webmainAction.php's publictreestore method. This vulnerability arises due to improper construction of SQL WHERE clauses, allowing remote attackers to manipulate SQL queries using the pidfields and idfields parameters. Consequently, attackers may gain unauthorized access to sensitive information stored in the database.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
