i-doit CMDB
cpe:2.3:a:i-doit:i-doit:*:*:*:*:*:*:*
- <= 1.12
A SQL injection vulnerability has been identified in i-doit CMDB version 1.12. This vulnerability allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the objGroupID parameter. Exploitation of this vulnerability could lead to the extraction of sensitive database information, including usernames, database names, and version details.
Exploitation of this vulnerability allows for arbitrary SQL execution, which could be used to manipulate the database or extract sensitive information.
To reproduce this vulnerability, send a GET request to the application with a crafted SQL payload in the objGroupID parameter. The injected SQL will be executed by the database, allowing the attacker to extract information such as usernames and database details.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.