In Janitza GridVis through 9.0.66, exposed dangerous methods in the de.janitza.pasw.project.server.ServerDatabaseProject project load functionality allow remote authenticated administrative users to execute arbitrary Groovy code.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gridvis | Janitza | * | 9.0.67 (excluding) |