VYPR

VoIPmonitor

by VoIPmonitor

CVEs (5)

  • CVE-2022-24260CriFeb 4, 2022
    risk 0.68cvss 9.8epss 0.50

    A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administrator level.

  • CVE-2021-30461CriMay 29, 2021
    risk 0.67cvss 9.8epss 0.37

    A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used, the user-supplied SPOOLDIR value (which might contain PHP code) is injected into config/configuration.php.

  • CVE-2021-41408CriJun 17, 2022
    risk 0.64cvss 9.8epss 0.01

    VoIPmonitor WEB GUI up to version 24.61 is affected by SQL injection through the "api.php" file and "user" parameter.

  • CVE-2022-24259CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.02

    An incorrect check in the component cdr.php of Voipmonitor GUI before v24.96 allows unauthenticated attackers to escalate privileges via a crafted request.

  • CVE-2022-24262HigFeb 4, 2022
    risk 0.57cvss 8.8epss 0.02

    The config restore function of Voipmonitor GUI before v24.96 does not properly check files sent as restore archives, allowing remote attackers to execute arbitrary commands via a crafted file in the web root.