ASUSTOR ADM version 3.1.0.RFQ3 is vulnerable to SQL injection via the album_id parameter in the /photo-gallery/api/album/tree_lists/ endpoint. An attacker can exploit this vulnerability to execute arbitrary SQL commands on the database, potentially leading to information disclosure or further compromise of the affected system.
id: CVE-2018-11511
info:
name: ASUSTOR ADM 3.1.0.RFQ3 - SQL Injection
author: ritikchaddha
se
...