High severity8.2NVD Advisory· Published Mar 21, 2026· Updated Jun 17, 2026
CVE-2019-25581
CVE-2019-25581
Description
i-doit CMDB 1.12 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the objGroupID parameter. Attackers can send GET requests with crafted SQL payloads in the objGroupID parameter to extract sensitive database information including usernames, database names, and version details.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- I-Doit/doit CMDBv5Range: 1.12
Patches
Vulnerability mechanics
References
4- www.exploit-db.com/exploits/46134nvdExploitThird Party AdvisoryVDB Entry
- www.vulncheck.com/advisories/i-doit-cmdb-sql-injection-via-objgroupid-parameternvdThird Party Advisory
- netcologne.dl.sourceforge.net/project/i-doit/i-doit/1.12/idoit-open-1.12.zipnvdProduct
- www.i-doit.orgnvdProduct
News mentions
0No linked articles in our index yet.