Vulnerabilities
2 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-25580 | ownDMS 4.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through th ownDMS 4.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the IMG parameter. Attackers can send GET requests to pdfstream.php, imagestream.php, or anyfilestream.php with crafted SQL payloads in the IMG parameter to extract sensitive database information including version and database names. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2018-18527 | OwnTicket 2018-05-23 allows SQL Injection via the showTicketId or editTicketStatusId parameter. OwnTicket 2018-05-23 allows SQL Injection via the showTicketId or editTicketStatusId parameter. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — |