


Perceptive Security
SOC/SIEM Consultancy

AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code t…
Published:
29 mei 2026 om 22:00:00
Alert date:
30 mei 2026 om 17:07:56
Source:
nvd.nist.gov
Web Technologies, Database & Storage
AiOPMSD Final 1.0.0 contains an SQL injection vulnerability in the 'id' parameter of watch.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can send crafted GET requests to extract sensitive database information including usernames, database names, and version details. The vulnerability affects the AiOPMSD application and allows unauthorized database access without authentication.
Technical details
Mitigation steps:
Affected products:
AiOPMSD Final
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2018-25420
https://aiopmsd.sourceforge.io/
https://sourceforge.net/projects/aiopmsd/files/latest/download
https://www.exploit-db.com/exploits/45690
https://www.vulncheck.com/advisories/aiopmsd-final-sql-injection-via-watch-php
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
