标题:ZEROF Web Server SQL注入漏洞
(CVE-2022-25322) Description:ZEROF Web Server是开源的一个简化现代Web开发的Web框架。它使您可以构建应用程序而不必担心程序包管理或路由。 ZEROF Web Server存在SQL注入漏洞,该漏洞允许HandleEvent SQL注入。
Description
ZEROF Web Server 2.0 allows SQL Injection via the /HandleEvent endpoint. Attackers can exploit this vulnerability by manipulating the request parameters to execute arbitrary SQL queries.