CVE-2020-18019
28.04.2021, 14:15
SQL Injection in Xinhu OA System v1.8.3 allows remote attackers to obtain sensitive information by injecting arbitrary commands into the "typeid" variable of the "createfolderAjax" function in the "mode_worcAction.php" component.
Vendor | Product | Version |
---|---|---|
xinfu | oa_system | 1.8.3 |
𝑥
= Vulnerable software versions