CVE-2019-9846

Publication date

2019-03-16 12:00:00

Family

mitre

State

PUBLISHED

Description

RockOA 1.8.7 allows remote attackers to obtain sensitive information because the webmain/webmainAction.php publictreestore method constructs a SQL WHERE clause unsafely by using the pidfields and idfields parameters, aka background SQL injection.