Summary
The commercial sipstation module allows administrators to inject arbitrary SQL commands into the database, even if they do not have specific access to the module.
Authentication with a known ACP user name is required.
Common Vulnerabilities and Exposures (CVE)
Requested
GitHub Security Advisory (GHSA)
GHSA-pq27-pw7r-4x8j
Provider Urgency (choice of: Not Defined, Clear, Green, Amber, or Red)
G - Green
Link to Published GHSA with More Details
Highlights
![]()