An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.
| Vendor | Product | Versions |
|---|---|---|
| sangoma | switchvox smb edition | 8.3 (104997) |
Loading…
Article classifies vulnerability as CRITICAL; updated severity from NONE and estimated CVSS to 9.0 based on critical classification and remote unauthenticated RCE potential.
Initial creation