← Back
Web Application
CVE-2026-19764 high CVSS 7.3

A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform...

Summary

A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform...

AI summary openai / gpt-4o

RaisecomのCommunication Command and Dispatch Management Platformのバージョン7.6.5までにSQLインジェクションの脆弱性が見つかりました。この脆弱性は、/app/users/getpwd.phpファイルの不明な部分に影響を与えます。攻撃者はリモートからこの脆弱性を悪用でき、既に実証済みのエクスプロイトが利用可能です。
❓ What is the problem
RaisecomのソフトウェアにおけるSQLインジェクションの脆弱性
📍 Affected scope
Communication Command and Dispatch Management Platformのバージョン7.6.5まで、/app/users/getpwd.phpファイル
🔥 Severity
リモートからSQLインジェクションが実行可能で、既に実証済みのエクスプロイトが存在するため、高リスク
🔧 How to fix
ベンダーからのパッチが提供されていないため、ソースコードのレビューを行い、SQLインジェクションを防ぐためのコード修正を施すこと
🛡️ Workaround
入力パラメータの検証とエスケーピングを強化して一時的に防御する
🔍 Detection
アプリケーションログやSQLログなどを監視し、不審なクエリの活動を確認する

References

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →