CVE-2021-47704
EUVD-2021-3473509.12.2025, 21:15
OpenBMCS 2.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting arbitrary SQL code. Attackers can send GET requests to /debug/obix_test.php with malicious 'id' values to extract database information.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| openbmcs | openbmcs | 2.4 |
𝑥
= Vulnerable software versions