| Issue: |
|
|---|---|
| Date: |
|
| Severity: | Critical |
| Requires Admin Access: | No |
| Fix Version: | 3.3.2, 3.5 |
| Credit: | Nicky @ Tencent Security Platform Department |
| Description: |
A SQL injection attack is possible via the Content REST api if the api is set to allow for anonymous content saving (which is the shipped default). |
| Mitigation: |
|
| References |
|