CVE-2019-15972
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists because the web-based management interface improperly validates SQL values. An attacker could exploit this vulnerability by authenticating to the application and sending malicious requests to an affected system. A successful exploit could allow the attacker to modify values on or return values from the underlying database.
- Affected products
- Cisco Unified Communications Manager
- Cisco Unified Communications Manager
- = 10.5\(2.10000.5\), 11.5\(1.10000.6\), 12.0\(1.10000.10\), 12.5\(1.10000.22\)
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 1.6% (73th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2019-11-26
No indexed exploits for CVE-2019-15972 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2019-15972 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.