An issue was discovered in the Archibus app 4.0.3 for iOS...
High severity
Unreviewed
Published
Feb 2, 2024
to the GitHub Advisory Database
•
Updated May 30, 2025
Description
Published by the National Vulnerability Database
Feb 2, 2024
Published to the GitHub Advisory Database
Feb 2, 2024
Last updated
May 30, 2025
An issue was discovered in the Archibus app 4.0.3 for iOS. It uses a local database that is synchronized with a Web central server instance every time the application is opened, or when the refresh button is used. There is a SQL injection in the search work request feature in the Maintenance module of the app. This allows performing queries on the local database.
References