CVE-2019-9846
EUVD-2019-1920228.06.2019, 16:15
RockOA 1.8.7 allows remote attackers to obtain sensitive information because the webmain/webmainAction.php publictreestore method constructs a SQL WHERE clause unsafely by using the pidfields and idfields parameters, aka background SQL injection.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| rockoa | rockoa | 𝑥 < 1.8.7 |
𝑥
= Vulnerable software versions