← Back to CVE List

CVE-2022-25225

Published: 2022-03-10T17:47Z
Last Modified: 2024-11-21T06:51Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Network Olympus version 1.8.0 allows an authenticated admin user to inject SQL queries in '/api/eventinstance' via the 'sqlparameter' JSON parameter. It is also possible to achieve remote code execution in the default installation (PostgreSQL) by exploiting this issue. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt