First published: Fri Aug 23 2019(Updated: )
The proxystatistics module before 3.1.0 for SimpleSAMLphp allows SQL Injection in lib/Auth/Process/DatabaseCommand.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cesnet Proxystatistics | <3.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15537 has a medium severity rating due to its potential for SQL Injection, which can lead to unauthorized database access.
To fix CVE-2019-15537, upgrade the Proxystatistics module to version 3.1.0 or later.
CVE-2019-15537 affects the Proxystatistics module for SimpleSAMLphp versions prior to 3.1.0.
CVE-2019-15537 is a SQL Injection vulnerability that allows attackers to execute arbitrary SQL queries.
The vendor associated with CVE-2019-15537 is CESNET, which maintains the Proxystatistics module.