GHSA-xpjx-348j-4qq5HighCVSS 8.2
The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated...
🔗 CVE IDs covered (1)
📋 Description
The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the tick_lat and tick_lng parameters. Attackers can send GET requests to nearby.php with crafted SQL payloads to extract sensitive database information including usernames, database names, and version details.
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2018-25399
- https://sourceforge.net/projects/openises/files/latest/download
- https://www.exploit-db.com/exploits/45645
- https://www.vulncheck.com/advisories/the-open-ises-project-3-30a-sql-injection-via-nearby-php
- http://openises.sourceforge.net
- https://github.com/advisories/GHSA-xpjx-348j-4qq5