A low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnostics_tab/ajax_diag_table_rows endpoint…
CERTVDE·CWE-497·Published 2026-09-16