Description
Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
Problem types
CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Any version before 2605
Credits
Dell would like to thank Duc Luong Tran (janlele91) and Huynh Dinh Vu (WinD39) for reporting this issue.
References
www.dell.com/support/kbdoc/en-us/000472001/dsa-2026-247