SQL-injection in Privileged Access Manager - CVE-2018-9029
Published: June 15, 2018
Privileged Access Manager
Detailed vulnerability description
The vulnerability exists due to insufficient validation on user-supplied input in multiple scripts. A remote attacker can send a specially crafted HTTP request to vulnerable script and execute arbitrary SQL commands in web application database.
Successful exploitation of the vulnerability may allow an attacker to gain administrative access to vulnerable web application.