Vulnerability Description
SQL injection vulnerability in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote authenticated users to execute arbitrary SQL commands via the filterPattern parameter.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dialogic | Powermedia Xms | <= 3.5 |
Related Weaknesses (CWE)
References
- https://d3adend.org/blog/?p=1398ExploitThird Party Advisory
- https://d3adend.org/blog/?p=1398ExploitThird Party Advisory
FAQ
What is CVE-2018-11643?
CVE-2018-11643 is a vulnerability with a CVSS score of 8.8 (HIGH). SQL injection vulnerability in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote authenticated users to execute arbitrary SQL commands via the filterPattern parameter.
How severe is CVE-2018-11643?
CVE-2018-11643 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-11643?
Check the references section above for vendor advisories and patch information. Affected products include: Dialogic Powermedia Xms.