CVE-2019-10852
23.05.2019, 19:29
Computrols CBAS 18.0.0 allows Authenticated Blind SQL Injection via the id GET parameter, as demonstrated by the index.php?m=servers&a=start_pulling&id= substring.
Vendor | Product | Version |
---|---|---|
computrols | computrols_building_automation_software | 𝑥 ≤ 19.0.0 |
𝑥
= Vulnerable software versions
References