vendor:
asterisk-addons
by:
Humberto J. Abdelnur, Radu State, Olivier Festor
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: asterisk-addons
Affected Version From: Prior to 1.2.8 when used with Asterisk Open Source 1.2.x, prior to 1.4.4 when used with Asterisk Open Source 1.4.x
Affected Version To: Not provided
Patch Exists: YES
Related CWE: Not provided
CPE: Not provided
Platforms Tested: Not provided
Unknown
Asterisk ‘asterisk-addons’ SQL Injection Vulnerability
The 'asterisk-addons' package in Asterisk Open Source versions 1.2.x and 1.4.x is prone to an SQL injection vulnerability. The vulnerability occurs because the application fails to sufficiently sanitize user-supplied data before using it in an SQL query. An attacker can exploit this vulnerability to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Mitigation:
To mitigate this vulnerability, it is recommended to update the 'asterisk-addons' package to version 1.2.8 or 1.4.4 or later.