Edirectory · Edirectory · CVE-2019-25675
**Name of the Vulnerable Software and Affected Versions**
eDirectory (affected versions not specified)
**Description**
Multiple SQL injection flaws allow unauthenticated attackers to bypass administrator authentication and disclose sensitive files. An attacker can use union-based SQL injection via the `key` parameter in the login endpoint to gain administrator access. Subsequently, they can exploit a file disclosure issue in the `language file.php` endpoint to read arbitrary PHP files from the server.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.