PT-2026-30507 · Edirectory · Edirectory
Efren Diaz
·
Published
2026-04-05
·
Updated
2026-04-05
·
CVE-2019-25675
CVSS v3.1
8.2
High
| AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
eDirectory contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to bypass administrator authentication and disclose sensitive files by injecting SQL code into parameters. Attackers can exploit the key parameter in the login endpoint with union-based SQL injection to authenticate as administrator, then leverage authenticated file disclosure vulnerabilities in language file.php to read arbitrary PHP files from the server.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Edirectory