TVN ID | TVN-202208003 |
---|---|
CVE ID | CVE-2022-38118 |
CVSS | 8.8 (High) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Affected Products | OAKlouds-mol_metting-2.0 <= OAKlouds-mol_metting-2.0-163 OAKlouds-mol_metting-3.0 <= OAKlouds-mol_metting-3.0-163 |
Description | OAKlouds Portal website’s Meeting Room has insufficient validation for user input. A remote attacker with general user privilege can perform SQL-injection to access, modify, delete database, perform system operations and disrupt service. |
Solution | OAKlouds-mol_metting-2.0 >= OAKlouds-mol_metting-2.0-164 OAKlouds-mol_metting-3.0 >= OAKlouds-mol_metting-3.0-164 |
Credit | Dong-Jie Chen (CHT Security) |
Public Date | 2022-08-30 |