CVE-2019-25438
Last modified
CVE-2019-25438 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. LabCollector 5.423 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL commands by injecting malicious code through POST parameters. Attackers can submit crafted SQL payloads in the login parameter of login.php or the user_name parameter of retrieve_password.php to extract sensitive database information without authentication.. EPSS estimates a 0.48% chance of exploitation in the next 30 days.
Description
LabCollector 5.423 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL commands by injecting malicious code through POST parameters. Attackers can submit crafted SQL payloads in the login parameter of login.php or the user_name parameter of retrieve_password.php to extract sensitive database information without authentication.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Agilebio | Labcollector | 5.423 |
References
- https://labcollector.com/Product
- https://www.exploit-db.com/exploits/47460Exploit, VDB Entry
- https://www.vulncheck.com/advisories/labcollector-sql-injection-via-loginphpThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-25438?
How severe is CVE-2019-25438?
How do I fix CVE-2019-25438?
Are you affected by CVE-2019-25438?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
