CVE Database
/

CVE-2022-25225

Back to search

CVE-2022-25225

Published: Mar 8, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

Network Olympus version 1.8.0 allows an authenticated admin user to inject SQL queries in '/api/eventinstance' via the 'sqlparameter' JSON parameter. It is also possible to achieve remote code execution in the default installation (PostgreSQL) by exploiting this issue.

VendorProductVersions

n/a

Network Olympus

affected
1.8.0

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now