RSA Web Threat Detection versions prior to 6.4, contain an SQL injection vulnerability in the Administration and Forensics applications. An authenticated malicious user with low privileges could potentially exploit this vulnerability to execute SQL commands on the back-end database to gain unauthorized access to the tool's monitoring and user information by supplying specially crafted input data to the affected application.
Use CWE-89, Rsa vendor hub and Web Threat Detection product page to widen CVE-2018-1252 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2014-4627, CVE-2015-4548 and CVE-2015-0541 for nearby disclosures in the same product family. Additional editorial context is available in Weekly Security Roundup: Navigating the April 2026 Threat Landscape and Critical Framework Exploits.