voipmonitor records
5 published records for vendor voipmonitor.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-287 Improper Authentication1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
54Plan | CVE-2022-24260Proof of concept | A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administrator level.voipmonitor · voipmonitor · CWE-89 | Critical9.8 | — | 50.0% | Feb 4, 2022 |
50Plan | CVE-2021-30461Proof of concept | A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61.voipmonitor · voipmonitor · CWE-94 | Critical9.8 | — | 36.6% | May 29, 2021 |
40Plan | CVE-2022-24259No exploit | An incorrect check in the component cdr.php of Voipmonitor GUI before v24.96 allows unauthenticated attackers to escalate privileges via a cvoipmonitor · voipmonitor · CWE-287 | Critical9.8 | — | 2.0% | Feb 4, 2022 |
39Monitor | CVE-2021-41408No exploit | VoIPmonitor WEB GUI up to version 24.61 is affected by SQL injection through the "api.php" file and "user" parameter.voipmonitor · voipmonitor · CWE-89 | Critical9.8 | — | 1.1% | Jun 17, 2022 |
36Monitor | CVE-2022-24262No exploit | The config restore function of Voipmonitor GUI before v24.96 does not properly check files sent as restore archives, allowing remote attackevoipmonitor · voipmonitor · CWE-434 | High8.8 | — | 1.8% | Feb 4, 2022 |
- CVE-2022-2426054Plan
A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administrator level.
CriticalCVSS 9.8Proof of conceptEPSS 50%voipmonitor · voipmonitorFeb 4, 2022
- CVE-2021-3046150Plan
A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61.
CriticalCVSS 9.8Proof of conceptEPSS 37%voipmonitor · voipmonitorMay 29, 2021
- CVE-2022-2425940Plan
An incorrect check in the component cdr.php of Voipmonitor GUI before v24.96 allows unauthenticated attackers to escalate privileges via a c
CriticalCVSS 9.8No exploitEPSS 2%voipmonitor · voipmonitorFeb 4, 2022
- CVE-2021-4140839Monitor
VoIPmonitor WEB GUI up to version 24.61 is affected by SQL injection through the "api.php" file and "user" parameter.
CriticalCVSS 9.8No exploitEPSS 1%voipmonitor · voipmonitorJun 17, 2022
- CVE-2022-2426236Monitor
The config restore function of Voipmonitor GUI before v24.96 does not properly check files sent as restore archives, allowing remote attacke
HighCVSS 8.8No exploitEPSS 2%voipmonitor · voipmonitorFeb 4, 2022