🟢 Authenticated admin SQL injection via SIPSTATION module

Summary

The commercial sipstation module allows administrators to inject arbitrary SQL commands into the database, even if they do not have specific access to the module.

Authentication with a known ACP user name is required.

Common Vulnerabilities and Exposures (CVE)

Requested

GitHub Security Advisory (GHSA)

GHSA-pq27-pw7r-4x8j

Provider Urgency (choice of: Not Defined, Clear, Green, Amber, or Red)

G - Green

Link to Published GHSA with More Details

Highlights

:green_circle: