Intel Data Center Manager 4.1 SQL Injection
Posted by deepcore on December 10, 2022 – 5:51 pm
Intel Data Center Manager’s endpoint at “/DcmConsole/DataAccessServlet?action=getRoomRackData” is vulnerable to an authenticated, blind SQL injection attack when user-supplied input to the HTTP POST parameter “dataName” is processed by the web application. Versions 4.1 and below are affected.
Post a reply
You must be logged in to post a comment.