Unrated severityNVD Advisory· Published Mar 30, 2020· Updated Aug 4, 2024
CVE-2020-5724
CVE-2020-5724
Description
The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote unauthenticated attacker can invoke the challenge action with a crafted username and discover user passwords.
Affected products
1- Range: 1.0.20.20 and below
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.tenable.com/security/research/tra-2020-17mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.