A critical SQL injection vulnerability exists in an unknown function of the file /OperateStatistic.do in Shenzhen Ruiming Technology Streamax Crocus 1.3.44. The manipulation of the argument VehicleID allows for remote exploitation without authentication, affecting confidentiality, integrity, and availability.
| Vendor | Product | Versions |
|---|---|---|
| shenzhen ruiming technology | streamax crocus | 1.3.44 |