Digiwin BPM’s function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL command to access, modify, delete database or disrupt service.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
digiwin business process management |