CVE-2019-1000023

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
04/02/2019
Last modified:
07/11/2023

Description

OPT/NET BV OPTOSS Next Gen Network Management System (NG-NetMS) version v3.6-2 and earlier versions contains a SQL Injection vulnerability in Identified vulnerable parameters: id, id_access_type and id_attr_access that can result in a malicious attacker can include own SQL commands which database will execute. This attack appears to be exploitable via network connectivity.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:opt-net:ng-netms:*:*:*:*:*:*:*:* 3.6-2 (including)