[0day-rubbish] Netsis NetOpenX REST 2.0.6.9 Unauthenticated SQL injection to xp_cmdshell SYSTEM command execution (9.8)
Logo Netsis NetOpenX REST 2.0.6.9 allows unauthenticated SQL injection that can run commands as SYSTEM.
0day Rubbish Research Team disclosed a flaw in Logo Netsis NetOpenX REST 2.0.6.9, the REST API gateway for the Netsis enterprise ERP suite. An unauthenticated SQL injection in the OAuth 2.0 token endpoint can lead to operating-system command execution through SQL Server xp_cmdshell. The issue is scored 9.8 and mapped to CWE-89, CWE-306, and CWE-78. The post cites no CVE and does not report exploitation in the wild.
73