Vulnerabilities > Nokia > Broadcast Message Center > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-05-25 CVE-2021-35487 SQL Injection vulnerability in Nokia Broadcast Message Center
Nokia Broadcast Message Center through 11.1.0 allows an authenticated user to perform a Boolean Blind SQL Injection attack on the endpoint /owui/block/send-receive-updates (for the Manage Alerts page) via the extIdentifier HTTP POST parameter.
network
low complexity
nokia CWE-89
6.5