Lucene search

K
prionPRIOn knowledge basePRION:CVE-2018-6393
HistoryJan 29, 2018 - 8:29 p.m.

Sql injection

2018-01-2920:29:00
PRIOn knowledge base
www.prio-n.com
6

7.3 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

74.9%

DISPUTED FreePBX 10.13.66-32bit and 14.0.1.24 (SNG7-PBX-64bit-1712-2) allow post-authentication SQL injection via the order parameter. NOTE: the vendor disputes this issue because it is intentional that a user can “directly modify SQL tables … [or] run shell scripts … once … logged in to the administration interface; there is no need to try to find input validation errors.”

CPENameOperatorVersion
freepbxeq10.13.66
freepbxeq14.0.1.24

7.3 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

74.9%

Related for PRION:CVE-2018-6393