| TVN ID | TVN-202208003 |
|---|---|
| CVE ID | CVE-2022-38118 |
| CVSS | 8.8 (High) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| Affected Products | OAKlouds-mol_metting-2.0 <= OAKlouds-mol_metting-2.0-163 OAKlouds-mol_metting-3.0 <= OAKlouds-mol_metting-3.0-163 |
| Description | OAKlouds Portal website’s Meeting Room has insufficient validation for user input. A remote attacker with general user privilege can perform SQL-injection to access, modify, delete database, perform system operations and disrupt service. |
| Solution | OAKlouds-mol_metting-2.0 >= OAKlouds-mol_metting-2.0-164 OAKlouds-mol_metting-3.0 >= OAKlouds-mol_metting-3.0-164 |
| Credit | Dong-Jie Chen (CHT Security) |
| Public Date | 2022-08-30 |
