top of page
perceptive_background_267k.jpg

eDirectory contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to bypass administrator authentication and disclose sensitive fi…

Published:

4 april 2026 om 22:00:00

Alert date:

5 april 2026 om 22:09:04

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications

eDirectory contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to bypass administrator authentication and disclose sensitive files. Attackers can exploit the key parameter in the login endpoint with union-based SQL injection to authenticate as administrator. Once authenticated, they can leverage file disclosure vulnerabilities in language_file.php to read arbitrary PHP files from the server. This represents a critical security flaw that provides complete administrative access without proper authentication.

Technical details

Mitigation steps:

Affected products:

eDirectory

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page