CVE-2020-3936

Publication date

2020-03-27 03:50:26

Family

twcert

State

PUBLISHED

Description

UltraLog Express device management interface does not properly filter user inputted string in some specific parameters, attackers can inject arbitrary SQL command.