OAKlouds Portal website’s Meeting Room has insufficient validation for user input. A remote attacker with general user privilege can perform SQL-injection to access, modify, delete database, perform system operations and disrupt service.Referenceshttps://www.twcert.org.tw/tw/cp-132-6461-25c4b-1.htmlhttps://www.chtsecurity.com/news/0a893178-5c64-4f1c-87f1-95cbf1e17c87