Security Advisory

CVE-2017-12710

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-08-30 18:00:00
Last updated 2024-08-05 18:43:56
Assigner icscert
CVSS score not scored
State PUBLISHED

Description

A SQL Injection issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. By submitting a specially crafted parameter, it is possible to inject arbitrary SQL statements that could allow an attacker to obtain sensitive information.