In multiple locations, there is a possible information disclosure due to SQL injection. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Denotes Vulnerable Software Are we missing a CPE here? Please let us know .
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
