SQL Injection Vulnerability in Rukovoditel by Rukovoditel
CVE-2020-11816
9.8CRITICAL
What is CVE-2020-11816?
Rukovoditel version 2.5.2 is prone to an SQL injection vulnerability due to improper handling of the 'reports_id' parameter in POST requests. Attackers could exploit this flaw to execute arbitrary SQL code, potentially accessing or modifying sensitive data, disrupting application functionality, or compromising the integrity of the underlying database.
