Description
|
|
A vulnerability has been reported in OpenVAS Manager, which can be exploited by malicious users to conduct SQL injection attacks.
Certain input related to the timezone parameter within the modify_schedule OMP command is not properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
Successful exploitation of this vulnerability requires permissions to modify schedule objects.
The vulnerability is reported in versions prior to 4.0.6.
|