Security Advisory

CVE-2020-13504

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2020-09-24 14:12:55
Last updated 2024-08-04 12:18:18
Assigner talos
State PUBLISHED

Description

Parameter AttFilterValue in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. An attacker can send unauthenticated HTTP requests to trigger this vulnerability.