CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.9. It affects Office. It involves a SQL injection risk. Exploitation may require the attacker to be authenticated.
CVE
CVE-2019-7001
Severity
CRITICAL
CVSS
9.9
EPSS
1.16%
Office
Original NVD Description
A SQL injection vulnerability in the WebUI component of IP Office Contact Center could allow an authenticated attacker to retrieve or alter sensitive data related to other users on the system. Affected versions of IP Office Contact Center include all 9.x and 10.x versions prior to 10.1.2.2.2-11201.1908. Unsupported versions not listed here were not evaluated.
Related CVEs
Other vulnerabilities affecting the same vendor(s)