CVE-2020-18106

EUVD-2020-10035
The GET parameter "id" in WMS v1.0 is passed without filtering, which allows attackers to perform SQL injection.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H