Security Advisory

CVE-2017-12585

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-08-06 03:00:00
Last updated 2024-09-16 23:26:55
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

SLiMS 8 Akasia through 8.3.1 has SQL injection in admin/AJAX_lookup_handler.php (tableName and tableFields parameters), admin/AJAX_check_id.php, and admin/AJAX_vocabolary_control.php. It can be exploited by remote authenticated librarian users.