Issue: |
|
---|---|
Date: |
|
Severity: | Critical |
Requires Admin Access: | No |
Fix Version: | 3.3.2, 3.5 |
Credit: | Nicky @ Tencent Security Platform Department |
Description: |
A SQL injection attack is possible via the Content REST api if the api is set to allow for anonymous content saving (which is the shipped default). |
Mitigation: |
|
References |
|