Security Advisory

CVE-2019-13489

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2019-07-10 21:18:52
Last updated 2024-08-04 23:57:39
Assigner mitre
State PUBLISHED

Description

Trape through 2019-05-08 has SQL injection via the data[2] variable in core/db.py, as demonstrated by the /bs t parameter.