An issue was discovered in TitanHQ WebTitan before 5.18. Some functions, such as /history-x.php, of the administration interface are vulnerable to SQL Injection through the results parameter. This could be used by an attacker to extract sensitive information from the appliance database.
References
Link Resource
https://write-up.github.io/webtitan/ Exploit Third Party Advisory
https://www.webtitan.com/resources/product-updates/ Release Notes Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2019-12-02T16:48:44

Updated: 2019-12-02T16:48:44

Reserved: 2019-11-17T00:00:00


Link: CVE-2019-19016

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-12-02T17:15:12.467

Modified: 2019-12-04T20:06:47.207


Link: CVE-2019-19016

JSON object: View

cve-icon Redhat Information

No data.

CWE