Product
high
advisory
Cross-Realm Information Disclosure in OpenRemote Notification API
1 TTP 1 CVEOpenRemote versions prior to 1.28.0 contain an information disclosure vulnerability in the Notification REST API that allows authenticated administrators to access sensitive data across all system realms.
OpenRemote
1t
1c
high
advisory
OpenRemote Authenticated SQL Injection via Datapoint Crosstab Export
1 TTPAn authenticated SQL injection vulnerability exists in the OpenRemote datapoint export API, allowing an attacker with asset creation/rename and datapoint export permissions to inject SQL commands via asset names, leading to arbitrary database execution and exfiltration of potentially cross-tenant data, with results returned in the normal ZIP/CSV export response.
openremote-manager +1
sql-injection
data-exfiltration
web-application
1t