cve/2022/CVE-2022-25225.md
2024-06-18 02:51:15 +02:00

777 B

CVE-2022-25225

Description

Network Olympus version 1.8.0 allows an authenticated admin user to inject SQL queries in '/api/eventinstance' via the 'sqlparameter' JSON parameter. It is also possible to achieve remote code execution in the default installation (PostgreSQL) by exploiting this issue.

POC

Reference

Github

No PoCs found on GitHub currently.