In Selesta Visual Access Manager < 4.42.2, an authenticated user can access the administrative page /common/vam_Sql.php, which allows for arbitrary SQL queries.
This Cyber News was published on www.tenable.com. Publication date: Tue, 14 Jan 2025 14:56:02 +0000