First published: Sat Mar 30 2019(Updated: )
Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to conduct SQL injection attacks via the sord parameter in a listCodeblueGroup API call to the /cgi? URI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Grandstream Ucm6204 Firmware | <1.0.19.20 | |
Grandstream UCM6204 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-10663.
The severity of CVE-2019-10663 is high with a score of 8.8.
Remote authenticated users can exploit CVE-2019-10663 by conducting SQL injection attacks via the sord parameter in a listCodeblueGroup API call to the /cgi? URI.
Grandstream UCM6204 devices before 1.0.19.20 are affected by CVE-2019-10663.
You can find more information about CVE-2019-10663 at this link: https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=23920&dl=1