VoIPmonitor
by VoIPmonitor
CVEs (5)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-24260 | Cri | 0.68 | 9.8 | 0.50 | Feb 4, 2022 | A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administrator level. | ||
| CVE-2021-30461 | Cri | 0.67 | 9.8 | 0.37 | May 29, 2021 | A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used, the user-supplied SPOOLDIR value (which might contain PHP code) is injected into config/configuration.php. | ||
| CVE-2021-41408 | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2022 | VoIPmonitor WEB GUI up to version 24.61 is affected by SQL injection through the "api.php" file and "user" parameter. | ||
| CVE-2022-24259 | Cri | 0.64 | 9.8 | 0.02 | Feb 4, 2022 | An incorrect check in the component cdr.php of Voipmonitor GUI before v24.96 allows unauthenticated attackers to escalate privileges via a crafted request. | ||
| CVE-2022-24262 | Hig | 0.57 | 8.8 | 0.02 | Feb 4, 2022 | The config restore function of Voipmonitor GUI before v24.96 does not properly check files sent as restore archives, allowing remote attackers to execute arbitrary commands via a crafted file in the web root. |
- risk 0.68cvss 9.8epss 0.50
A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administrator level.
- risk 0.67cvss 9.8epss 0.37
A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used, the user-supplied SPOOLDIR value (which might contain PHP code) is injected into config/configuration.php.
- risk 0.64cvss 9.8epss 0.01
VoIPmonitor WEB GUI up to version 24.61 is affected by SQL injection through the "api.php" file and "user" parameter.
- risk 0.64cvss 9.8epss 0.02
An incorrect check in the component cdr.php of Voipmonitor GUI before v24.96 allows unauthenticated attackers to escalate privileges via a crafted request.
- risk 0.57cvss 8.8epss 0.02
The config restore function of Voipmonitor GUI before v24.96 does not properly check files sent as restore archives, allowing remote attackers to execute arbitrary commands via a crafted file in the web root.