CVE-2019-9846: SQL Injection
RockOA 1.8.7 allows remote attackers to obtain sensitive information because the webmain/webmainAction.php publictreestore method constructs a SQL WHERE clause unsafely by using the pidfields and idfields parameters, aka background SQL injection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-9846?
CVE-2019-9846 is classified as having a medium severity due to its potential for SQL injection that may lead to sensitive information disclosure.
How do I fix CVE-2019-9846?
To fix CVE-2019-9846, update RockOA to version 1.8.7 or a later version to ensure secure handling of input parameters.
What type of vulnerability is CVE-2019-9846?
CVE-2019-9846 is a background SQL injection vulnerability affecting RockOA's webmainAction.php script.
What are the potential impacts of CVE-2019-9846?
The potential impacts of CVE-2019-9846 include unauthorized access to sensitive information from the database.
Which versions of RockOA are affected by CVE-2019-9846?
CVE-2019-9846 affects RockOA versions prior to 1.8.7.