CVE-2020-18713: SQL Injection
Published Feb 4, 2021
·Updated
SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in customerAction.php
Affected Software
1 affected component
Rockoa RockOA=1.8.7
Event History
Feb 4, 2021
CVE Published
via MITRE·11:01 PM
Data Sourced
via MITRE·11:01 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-18713?
CVE-2020-18713 has a medium severity rating due to its potential for SQL injection attacks.
2
How do I fix CVE-2020-18713?
To fix CVE-2020-18713, upgrade to a version of Rockoa that addresses SQL injection issues.
3
What systems are affected by CVE-2020-18713?
CVE-2020-18713 affects Rockoa version 1.8.7.
4
Can CVE-2020-18713 be exploited remotely?
Yes, CVE-2020-18713 can be exploited remotely due to loose parameter filtering.
5
What actions should I take if I am using Rockoa v1.8.7 in relation to CVE-2020-18713?
If you are using Rockoa v1.8.7, it is essential to implement security patches or upgrade to mitigate CVE-2020-18713.