SQL Injection Vulnerability in Rukovoditel by Fatihh Celik
CVE-2020-11812
9.8CRITICAL
What is CVE-2020-11812?
Rukovoditel 2.5.2 contains a SQL injection vulnerability due to improper handling of the filters[0][value] and filters[1][value] parameters. An attacker can exploit this flaw to execute arbitrary SQL commands within the application's database. This could lead to unauthorized access to sensitive data, data corruption, or even complete control over the database server.
