سيبرانا

قاعدة الثغرات (CVE)

CVE-2026-9586

حقن SQL دون مصادقة في Sangoma Switchvox

حرجةمُستغلة فعليًاKEVالتصحيح متوفر: غير متوفر بعد

طلب واحد مصمَّم يسمح لمهاجم عن بُعد غير مصادَق بتنفيذ عبارات SQL عشوائية ضد قاعدة PostgreSQL الخلفية لنظام الهاتف Switchvox، بما فيها قراءة بيانات الاعتماد.

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.

المنتجات المتأثرة

Productالإصدارات المتأثرةتم الإصلاح في
Switchvox

التغطية على سيبرانا