Files
CVEs-PoC/2017/CVE-2017-12585.md
2025-09-29 21:09:30 +02:00

726 B

CVE-2017-12585

Description

SLiMS 8 Akasia through 8.3.1 has SQL injection in admin/AJAX_lookup_handler.php (tableName and tableFields parameters), admin/AJAX_check_id.php, and admin/AJAX_vocabolary_control.php. It can be exploited by remote authenticated librarian users.

POC

Reference

Github

No PoCs found on GitHub currently.