CVE-2026-19764: Raisecom Communication Command and Dispatch Management Platform getpwd.php sql injection
A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform up to 7.6.5. This affects an unknown part of the file /app/users/getpwd.php. Such manipulation of the argument sip leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19764?
The severity of CVE-2026-19764 is high, with a score of 7.3.
What is the risk associated with CVE-2026-19764?
CVE-2026-19764 has a risk rating of 52.
How does CVE-2026-19764 affect the Raisecom Communication Command and Dispatch Management Platform?
CVE-2026-19764 allows for SQL injection through the getpwd.php file, potentially exposing sensitive data.
How can I fix CVE-2026-19764?
To fix CVE-2026-19764, it's recommended to patch or upgrade the Raisecom Communication Command and Dispatch Management Platform to version 7.6.6 or later.
Can CVE-2026-19764 be exploited remotely?
Yes, CVE-2026-19764 can be exploited remotely by manipulating the sip argument in the getpwd.php file.