← Back to CVE List

CVE-2018-5384

Published: 2018-07-24T15:29Z
Last Modified: 2024-11-21T04:08Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Navarino Infinity web interface up to version 2.2 exposes an unauthenticated script that is prone to blind sql injection. If successfully exploited the user can get info from the underlying postgresql database that could lead into to total compromise of the product. The said script is available with no authentication. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt