Navarino Infinity web interface up to version 2.2 exposes an unauthenticated script that is prone to blind sql injection. If successfully exploited the user can get info from the underlying postgresql database that could lead into to total compromise of the product. The said script is available with no authentication.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published: 2018-07-24T15:00:00

Updated: 2024-08-05T05:33:44.385Z

Reserved: 2018-01-12T00:00:00

Link: CVE-2018-5384

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-07-24T15:29:01.030

Modified: 2023-11-07T02:58:42.063

Link: CVE-2018-5384

cve-icon Redhat

No data.