Vulnerabilities (CVE)

Filtered by vendor Softinventive Subscribe
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-25225 1 Softinventive 1 Network Olympus 2024-02-28 6.5 MEDIUM 7.2 HIGH
Network Olympus version 1.8.0 allows an authenticated admin user to inject SQL queries in '/api/eventinstance' via the 'sqlparameter' JSON parameter. It is also possible to achieve remote code execution in the default installation (PostgreSQL) by exploiting this issue.