Retour à la veille

CVE-2026-79573

Publié : 8 septembre 2026
Modifié : 8 septembre 2026
Lien officiel NVD

Description détaillée

L-ONE v1.0.0 was discovered to contain multiple SQL injection vulnerabilities in the /attachment/getBusinessUploadList component via the busid, id, and taskid parameters. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.

Références et Patchs