Vulnerability Description
Synetics GmbH I-doit 1.12 and earlier is affected by: SQL Injection. The impact is: Unauthenticated mysql database access. The component is: Web login form. The attack vector is: An attacker can exploit the vulnerability by sending a malicious HTTP POST request. The fixed version is: 1.12.1.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| I-Doit | I-Doit | <= 1.12 |
Related Weaknesses (CWE)
References
- https://sourceforge.net/projects/i-doit/files/i-doit/1.12.1/CHANGELOG/downloadRelease NotesThird Party Advisory
- https://sourceforge.net/projects/i-doit/files/i-doit/1.12.1/CHANGELOG/downloadRelease NotesThird Party Advisory
FAQ
What is CVE-2019-1010248?
CVE-2019-1010248 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Synetics GmbH I-doit 1.12 and earlier is affected by: SQL Injection. The impact is: Unauthenticated mysql database access. The component is: Web login form. The attack vector is: An attacker can explo...
How severe is CVE-2019-1010248?
CVE-2019-1010248 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-1010248?
Check the references section above for vendor advisories and patch information. Affected products include: I-Doit I-Doit.