
CVE-2018-25194 Nominas 0.27 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the us… https://www.cve.org/CVERecord?id=CVE-2018-25194
Post summary
The post reports a disclosed SQL injection flaw in Nominas 0.27 that enables unauthenticated attackers to run arbitrary SQL queries, with no evidence of exploits or patches.
