Vulnerabilities (CVE)

Filtered by vendor Voipmonitor Subscribe
Filtered by product Voipmonitor
Total 5 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-41408 1 Voipmonitor 1 Voipmonitor 2024-02-04 7.5 HIGH 9.8 CRITICAL
VoIPmonitor WEB GUI up to version 24.61 is affected by SQL injection through the "api.php" file and "user" parameter.
CVE-2022-24259 1 Voipmonitor 1 Voipmonitor 2024-02-04 7.5 HIGH 9.8 CRITICAL
An incorrect check in the component cdr.php of Voipmonitor GUI before v24.96 allows unauthenticated attackers to escalate privileges via a crafted request.
CVE-2022-24262 1 Voipmonitor 1 Voipmonitor 2024-02-04 6.5 MEDIUM 8.8 HIGH
The config restore function of Voipmonitor GUI before v24.96 does not properly check files sent as restore archives, allowing remote attackers to execute arbitrary commands via a crafted file in the web root.
CVE-2022-24260 1 Voipmonitor 1 Voipmonitor 2024-02-04 10.0 HIGH 9.8 CRITICAL
A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administrator level.
CVE-2021-30461 1 Voipmonitor 1 Voipmonitor 2024-02-04 7.5 HIGH 9.8 CRITICAL
A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used, the user-supplied SPOOLDIR value (which might contain PHP code) is injected into config/configuration.php.