Beveiligingsadvies

CVE-2018-25173

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-03-06 12:19:04
Laatst bijgewerkt 2026-03-09 15:26:56
Toegewezen door VulnCheck
CVSS-score 8.8
Status PUBLISHED

Beschrijving

Rmedia SMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the gid parameter. Attackers can send GET requests to editgrp.php with malicious gid values using EXTRACTVALUE and CONCAT functions to retrieve schema names and sensitive database data.