Vulnerability Details CVE-2019-18663
A SQL injection vulnerability in a /login/forgot1 POST request in ARP-GUARD 4.0.0-5 allows unauthenticated remote attackers to execute arbitrary SQL commands via the user_id parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.017
EPSS Ranking 81.8%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2019-18663
-
cpe:2.3:a:isl:arp-guard:4.0.0-5