CVE-2018-11511: SQL Injection
Published Aug 16, 2018
·Updated
The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability that affects the 'albumid' or 'scope' parameter via a photo-gallery/api/album/treelists/ URI.
Affected Software
1 affected component
ASUSTOR Asustor Data Master=3.1.0
Event History
Aug 16, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the CVE ID for this vulnerability?
The CVE ID for this vulnerability is CVE-2018-11511.
2
What is the severity of CVE-2018-11511?
The severity of CVE-2018-11511 is critical with a score of 9.8.
3
What is the affected software?
The affected software is ASUSTOR ADM 3.1.0.RFQ3.
4
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-89.
5
How can I fix CVE-2018-11511 vulnerability?
To fix the CVE-2018-11511 vulnerability, ensure that you are using the latest version of ASUSTOR ADM and apply any available patches or updates from the software vendor.