Damstra Smart Asset 2020.7 has SQL injection via the API/api/Asset originator parameter. This allows forcing the database and server to initiate remote connections to third party DNS servers.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26525
Reference (s):
- https://github.com/lukaszstu/SmartAsset-SQLinj-CVE-2020-26525/blob/main/README.md
- https://support.damstratechnology.com/hc/en-us/categories/900000115446-SmartAsset-Damstra-Asset-Management-Platform
- https://www.smartasset.com.au/

