← Back

Voipmonitor

voipmonitor

Vendor: Voipmonitor • 5 CVEs

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Voipmonitor
1Voipmonitor
Nov 21, 2024
Jun 17, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
VoIPmonitor WEB GUI up to version 24.61 is affected by SQL injection through the "api.php" file and "user" parameter.
1Voipmonitor
1Voipmonitor
Nov 21, 2024
Feb 4, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The config restore function of Voipmonitor GUI before v24.96 does not properly check files sent as restore archives, allowing remote attackers to execute arbitrary commands via a crafted file in the web root.
1Voipmonitor
1Voipmonitor
Nov 21, 2024
Feb 4, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administrator level.
1Voipmonitor
1Voipmonitor
Nov 21, 2024
Feb 4, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An incorrect check in the component cdr.php of Voipmonitor GUI before v24.96 allows unauthenticated attackers to escalate privileges via a crafted request.
1Voipmonitor
1Voipmonitor
Nov 21, 2024
May 29, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used, the user-supplied SPOOLDIR value (which might contain PHP code) is injected into config/configurati...Show more
A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used, the user-supplied SPOOLDIR value (which might contain PHP code) is injected into config/configuration.php.Show less