ZEROF Web Server 2.0 allows SQL Injection via the /HandleEvent endpoint. Attackers can exploit this vulnerability by manipulating the request parameters to execute arbitrary SQL queries.
id: CVE-2022-25322
info:
name: ZEROF Web Server 2.0 - SQL Injection
author: daffainfo
severit
...