Filtered by vendor Voipmonitor
Subscriptions
Filtered by product Voipmonitor
Subscriptions
Total
5 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-24262 | 1 Voipmonitor | 1 Voipmonitor | 2024-11-21 | 8.8 High |
| The config restore function of Voipmonitor GUI before v24.96 does not properly check files sent as restore archives, allowing remote attackers to execute arbitrary commands via a crafted file in the web root. | ||||
| CVE-2022-24260 | 1 Voipmonitor | 1 Voipmonitor | 2024-11-21 | 9.8 Critical |
| A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administrator level. | ||||
| CVE-2022-24259 | 1 Voipmonitor | 1 Voipmonitor | 2024-11-21 | 9.8 Critical |
| An incorrect check in the component cdr.php of Voipmonitor GUI before v24.96 allows unauthenticated attackers to escalate privileges via a crafted request. | ||||
| CVE-2021-41408 | 1 Voipmonitor | 1 Voipmonitor | 2024-11-21 | 9.8 Critical |
| VoIPmonitor WEB GUI up to version 24.61 is affected by SQL injection through the "api.php" file and "user" parameter. | ||||
| CVE-2021-30461 | 1 Voipmonitor | 1 Voipmonitor | 2024-11-21 | 9.8 Critical |
| A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used, the user-supplied SPOOLDIR value (which might contain PHP code) is injected into config/configuration.php. | ||||
Page 1 of 1.