si1ence90/xinhu1.8.3_SqlInject

si1ence90/xinhu1.8.3_SqlInject

Releases0
Stars1

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH5 MEDIUM

SQL Injection in Xinhu OA System v1.8.3 allows remote attackers to obtain sensitive information by injecting arbitrary commands into the "typeid" variable of the "createfolderAjax" function in the "mode_worcAction.php" component.