Уязвимость внедрения SQL-кода в Bottinelli Informatica Vedo Suite v.1.2.5 позволяет удаленному злоумышленнику выполнить произвольный код через конечную точку api_vedo/chat и параметр utente_chat.
Показать оригинальное описание (EN)
SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to execute arbitrary code via the api_vedo/chat endpoint and the utente_chat parameter