
Disclosure of a SQL injection vulnerability in ScienceLogic web platform (index.em7) affecting versions prior to 12.1.1, with mitigation guidance and responsible disclosure details.
This document outlines a responsibly disclosed SQL injection vulnerability found in ScienceLogic's web platform. The vulnerability has been reported to the project maintainers in accordance with responsible disclosure practices to ensure timely mitigation and protection of users.
An SQL injection vulnerability was identified in ScienceLogic's web platform, specifically in the index.em7 file. A parameter passed as part of a request can be supplied with SQL statements, allowing an attacker to manipulate the database request and potentially gain unauthorized access to sensitive data or control over the database.
This vulnerability was disclosed following responsible disclosure principles:
Thanks to ScienceLogic for their cooperation in addressing this vulnerability promptly.