CVE-2017-12729

CRITICAL

Moxa SoftCMS Live Viewer < 1.6 - SQL Injection

Title source: llm
STIX 2.1

Description

A SQL Injection issue was discovered in Moxa SoftCMS Live Viewer through 1.6. An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability has been identified. Attackers can exploit this vulnerability to access SoftCMS without knowing the user's password.

References (1)

Core 1
Core References
Mitigation, Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-17-243-05

Scores

CVSS v3 9.8
EPSS 0.0020
EPSS Percentile 42.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
moxa/softcms_lab_view < 1.6
Published Jan 18, 2018
Tracked Since Feb 18, 2026