Lucene search

K
cvelistMitreCVELIST:CVE-2018-6393
HistoryJan 29, 2018 - 8:00 p.m.

CVE-2018-6393

2018-01-2920:00:00
mitre
www.cve.org

7.4 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

74.9%

FreePBX 10.13.66-32bit and 14.0.1.24 (SNG7-PBX-64bit-1712-2) allow post-authentication SQL injection via the order parameter. NOTE: the vendor disputes this issue because it is intentional that a user can "directly modify SQL tables … [or] run shell scripts … once … logged in to the administration interface; there is no need to try to find input validation errors.

7.4 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

74.9%

Related for CVELIST:CVE-2018-6393