CVE-2018-1000631: Battelle v2i Hub
Critical severity, CVSS 9.8. EPSS: 2.3% chance of exploitation in the next 30 days.
Battelle V2I Hub 3.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements to the tmx/TmxCtl/src/lib/PluginStatus.cpp and TmxControl::user_info() function, which could allow the attacker to view, add, modify or delete information in the back-end database.
Affected products
- Battelle v2i Hub: version 3.0 only
Published 2018-12-28. Last modified 2026-06-17.