CVE-2019-10663: SQL Injection
Published Mar 30, 2019
·Updated
Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to conduct SQL injection attacks via the sord parameter in a listCodeblueGroup API call to the /cgi? URI.
Affected Software
2 affected components
Grandstream Ucm6204 Firmware<1.0.19.20
Grandstream UCM6204
Event History
Mar 30, 2019
CVE Published
via MITRE·04:43 PM
Data Sourced
via MITRE·04:43 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2019-10663.
2
What is the severity of CVE-2019-10663?
The severity of CVE-2019-10663 is high with a score of 8.8.
3
How can remote authenticated users exploit CVE-2019-10663?
Remote authenticated users can exploit CVE-2019-10663 by conducting SQL injection attacks via the sord parameter in a listCodeblueGroup API call to the /cgi? URI.
4
Which version of Grandstream UCM6204 devices are affected by CVE-2019-10663?
Grandstream UCM6204 devices before 1.0.19.20 are affected by CVE-2019-10663.
5
Where can I find more information about CVE-2019-10663?
You can find more information about CVE-2019-10663 at this link: https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=23920&dl=1