CVE-2018-12482: SQL Injection
Published Aug 3, 2018
·Updated
OCS Inventory 2.4.1 contains multiple SQL injections in the search engine. Authentication is needed in order to exploit the issues.
Affected Software
1 affected component
Ocsinventory-ng Ocsinventory Ng=2.4.1
Event History
Aug 3, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-12482?
CVE-2018-12482 is classified as a high severity vulnerability due to the potential for SQL injection attacks.
2
How do I fix CVE-2018-12482?
To fix CVE-2018-12482, upgrade OCS Inventory to the latest version that does not contain this vulnerability.
3
What are the implications of CVE-2018-12482?
Exploitation of CVE-2018-12482 can lead to unauthorized access to sensitive data through SQL injection techniques.
4
Is authentication required to exploit CVE-2018-12482?
Yes, authentication is required to exploit the SQL injection vulnerabilities identified in CVE-2018-12482.
5
Which software versions are affected by CVE-2018-12482?
CVE-2018-12482 specifically affects OCS Inventory version 2.4.1.