SUNNET WMPro portal's FAQ function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL commands to obtain sensitive information via a database.
2023-09-18T03:15:08.017
2024-11-21T08:08:49.380
Modified
CVSSv3.1: 7.5 (HIGH)