First published: Mon May 13 2019(Updated: )
SQL injection in folderViewSpecific.psp in Seagate NAS OS version 4.3.15.1 allows attackers to execute arbitrary SQL commands via the dirId URL parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Seagate NAS OS | =4.3.15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-12295 is classified as a high-severity vulnerability due to the potential for remote SQL injection.
To fix CVE-2018-12295, upgrade Seagate NAS OS to a version later than 4.3.15.1 that addresses the SQL injection flaw.
The risks associated with CVE-2018-12295 include unauthorized data access and potential data manipulation through SQL injection.
If you are running Seagate NAS OS version 4.3.15.1, your system is vulnerable to CVE-2018-12295.
CVE-2018-12295 affects the folderViewSpecific.psp component in Seagate NAS OS version 4.3.15.1.