i-doit CMDB 1.12 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the objGroupID parameter. Attackers can send GET requests with crafted SQL payloads in the objGroupID parameter to extract sensitive database information including usernames, database names, and version details.
Metrics
Affected Vendors & Products
References
History
Sat, 21 Mar 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | i-doit CMDB 1.12 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the objGroupID parameter. Attackers can send GET requests with crafted SQL payloads in the objGroupID parameter to extract sensitive database information including usernames, database names, and version details. | |
| Title | i-doit CMDB 1.12 SQL Injection via objGroupID Parameter | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-21T15:30:39.536Z
Reserved: 2026-03-21T15:29:20.744Z
Link: CVE-2019-25581
No data.
Status : Received
Published: 2026-03-21T16:16:02.303
Modified: 2026-03-21T16:16:02.303
Link: CVE-2019-25581
No data.
OpenCVE Enrichment
No data.