CVE-2020-18716: SQL Injection
Published Feb 4, 2021
·Updated
SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordAction.php.
Affected Software
1 affected component
Rockoa RockOA=1.8.7
Event History
Feb 4, 2021
CVE Published
via MITRE·11:15 PM
Data Sourced
via MITRE·11:15 PM
Description
Frequently Asked Questions
1
What is CVE-2020-18716?
CVE-2020-18716 is a SQL Injection vulnerability in Rockoa v1.8.7 that allows remote attackers to gain privileges due to loose filtering of parameters in wordAction.php.
2
How severe is CVE-2020-18716?
CVE-2020-18716 is categorized as critical with a severity score of 9.8.
3
What software versions are affected by CVE-2020-18716?
Rockoa v1.8.7 is affected by CVE-2020-18716.
4
How can remote attackers exploit CVE-2020-18716?
Remote attackers can exploit CVE-2020-18716 by performing SQL Injection attacks through the wordAction.php file.
5
Is there a fix available for CVE-2020-18716?
Currently, there is no information available regarding an official fix for CVE-2020-18716.