قاعدة الثغرات (CVE)
CVE-2026-9586
حقن SQL دون مصادقة في Sangoma Switchvox
حرجةمُستغلة فعليًاKEVالتصحيح متوفر: غير متوفر بعد
طلب واحد مصمَّم يسمح لمهاجم عن بُعد غير مصادَق بتنفيذ عبارات SQL عشوائية ضد قاعدة PostgreSQL الخلفية لنظام الهاتف Switchvox، بما فيها قراءة بيانات الاعتماد.
An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.
المنتجات المتأثرة
| Product | الإصدارات المتأثرة | تم الإصلاح في |
|---|---|---|
| Switchvox | — | — |
التغطية على سيبرانا
—