8.8
CVSSv3

CVE-2019-15972

Published: 26/11/2019 Updated: 09/12/2019
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 580
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote malicious user to conduct SQL injection attacks on an affected system. The vulnerability exists because the web-based management interface improperly validates SQL values. An attacker could exploit this vulnerability by authenticating to the application and sending malicious requests to an affected system. A successful exploit could allow the malicious user to modify values on or return values from the underlying database.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified communications manager 10.5\\(2.10000.5\\)

cisco unified communications manager 11.5\\(1.10000.6\\)

cisco unified communications manager 12.0\\(1.10000.10\\)

cisco unified communications manager 12.5\\(1.10000.22\\)

Vendor Advisories

A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system The vulnerability exists because the web-based management interface improperly validates SQL values An attacker could exploit this vulnerability by authe ...

Github Repositories

Scripts that can be used to exploit CVE-2019-15972 which was an Authenticated SQLi issue in Cisco Unified Call Manager (UCM).

CVE-2019-15972 Cisco UCM SQLi Scripts Scripts that can be used to exploit CVE-2019-15972 which was an Authenticated SQLi issue in Cisco Unified Call Manager (UCM) Enumerate tables - enumerate all tables on the underlying database and place the table names in a text file Extract tables - take the list of tables and extract the contents of each table Related F-Secure advisory c

Scripts that can be used to exploit CVE-2019-15972 which was an Authenticated SQLi issue in Cisco Unified Call Manager (UCM).

CVE-2019-15972 Cisco UCM SQLi Scripts Scripts that can be used to exploit CVE-2019-15972 which was an Authenticated SQLi issue in Cisco Unified Call Manager (UCM) Enumerate tables - enumerate all tables on the underlying database and place the table names in a text file Extract tables - take the list of tables and extract the contents of each table Related F-Secure advisory c