CVE-2019-19016

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
02/12/2019
Last modified:
04/12/2019

Description

An issue was discovered in TitanHQ WebTitan before 5.18. Some functions, such as /history-x.php, of the administration interface are vulnerable to SQL Injection through the results parameter. This could be used by an attacker to extract sensitive information from the appliance database.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:titanhq:webtitan:*:*:*:*:*:*:*:* 5.18 (excluding)