GHSA-xjc6-w655-p4pcHighCVSS 8.2
The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated...
🔗 CVE IDs covered (1)
📋 Description
The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the ticket_id parameter. Attackers can send GET requests to add_facnote.php with crafted SQL payloads to extract sensitive database information including version details and other data.
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2018-25404
- https://sourceforge.net/projects/openises/files/latest/download
- https://www.exploit-db.com/exploits/45645
- https://www.vulncheck.com/advisories/the-open-ises-project-3-30a-sql-injection-via-add-facnote-php
- http://openises.sourceforge.net
- https://github.com/advisories/GHSA-xjc6-w655-p4pc