CVE-2019-15537: SQL Injection
Published Aug 23, 2019
·Updated
The proxystatistics module before 3.1.0 for SimpleSAMLphp allows SQL Injection in lib/Auth/Process/DatabaseCommand.php.
Affected Software
1 affected component
CESNET Proxystatistics Simplesamlphp<3.1.0
Remediation
Event History
Aug 23, 2019
CVE Published
via MITRE·05:49 PM
Data Sourced
via MITRE·05:49 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-15537?
CVE-2019-15537 has a medium severity rating due to its potential for SQL Injection, which can lead to unauthorized database access.
2
How do I fix CVE-2019-15537?
To fix CVE-2019-15537, upgrade the Proxystatistics module to version 3.1.0 or later.
3
What software is affected by CVE-2019-15537?
CVE-2019-15537 affects the Proxystatistics module for SimpleSAMLphp versions prior to 3.1.0.
4
What is the nature of the vulnerability CVE-2019-15537?
CVE-2019-15537 is a SQL Injection vulnerability that allows attackers to execute arbitrary SQL queries.
5
Who is the vendor associated with CVE-2019-15537?
The vendor associated with CVE-2019-15537 is CESNET, which maintains the Proxystatistics module.