


Perceptive Security
SOC/SIEM Consultancy

The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting maliciou…
Published:
28 mei 2026 om 22:00:00
Alert date:
29 mei 2026 om 17:11:07
Source:
nvd.nist.gov
Web Technologies, Database & Storage
The Open ISES Project version 3.30A contains a critical SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries through the p1 parameter in sever_graph.php. Attackers can send crafted GET requests with malicious SQL payloads to extract sensitive database information including schema names and other data. This vulnerability poses a significant risk as it requires no authentication and can lead to complete database compromise.
Technical details
Mitigation steps:
Affected products:
The Open ISES Project
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2018-25401
http://openises.sourceforge.net/
https://sourceforge.net/projects/openises/files/latest/download
https://www.exploit-db.com/exploits/45645
https://www.vulncheck.com/advisories/the-open-ises-project-3-30a-sql-injection-via-sever-graph-php
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
