Security Advisory

CVE-2022-25225

7.2
HIGH

Vulnerability Description

Network Olympus version 1.8.0 allows an authenticated admin user to inject SQL queries in '/api/eventinstance' via the 'sqlparameter' JSON parameter. It is also possible to achieve remote code execution in the default installation (PostgreSQL) by exploiting this issue.
Published Date March 10, 2022
Official Source NIST NVD Advisory