CVE-2021-37749
30.08.2021, 04:15
MapService.svc in Hexagon GeoMedia WebMap 2020 before Update 2 (aka 16.6.2.66) allows blind SQL Injection via the Id (within sourceItems) parameter to the GetMap method.
Vendor | Product | Version |
---|---|---|
hexagongeospatial | geomedia_webmap | 𝑥 < 16.6.2.66 |
𝑥
= Vulnerable software versions
References