CVE-2020-25143
It is vulnerable to SQL Injection due to the fact that it is possible to inject malicious SQL statements in malformed parameter types.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.19%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to SQL Injection due to the fact that it is possible to inject malicious SQL statements in malformed parameter types. This can occur via /ajax/device_entities.php?entity_type=netscalervsvr&device_id[]= because of /ajax/device_entities.php.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.19% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- observium/observium
- Source
- cve@mitre.org
References
- https://gist.github.com/ahpaleus/e75388086061ce52616967ba9ec63820Third Party Advisory
- https://gist.github.com/ahpaleus/e75388086061ce52616967ba9ec63820Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.