CVE-2018-11511: exploitation status and patch state
CVE-2018-11511 · CVSS 9.8 CRITICAL · EPSS 11%
The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability that affects the 'album_id' or 'scope' parameter via a photo-gallery/api/album/tree_lists/ URI.
Is CVE-2018-11511 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at 11%.