Learn about CVE-2019-19986, a SQL Injection vulnerability in Selesta Visual Access Manager versions 4.15.0 to 4.29. Find out how to mitigate the risk and protect your systems.
A vulnerability was found in Selesta Visual Access Manager (VAM) versions 4.15.0 to 4.29 that allows unauthorized users to execute SQL SELECT statements through injection.
Understanding CVE-2019-19986
This CVE identifies a SQL Injection vulnerability in Selesta Visual Access Manager (VAM) versions 4.15.0 to 4.29.
What is CVE-2019-19986?
The vulnerability allows unauthorized users to execute SQL SELECT statements by injecting the persoid parameter into the /tools/VamPersonPhoto.php file using HTTP POST or GET methods.
The Impact of CVE-2019-19986
Unauthorized users can exploit this issue to gain access to sensitive information by manipulating SQL queries through injection techniques.
Technical Details of CVE-2019-19986
This section provides detailed technical information about the vulnerability.
Vulnerability Description
The vulnerability in Selesta Visual Access Manager (VAM) versions 4.15.0 to 4.29 allows attackers to execute arbitrary SQL SELECT statements by injecting the persoid parameter into /tools/VamPersonPhoto.php.
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Protect your systems from CVE-2019-19986 with these mitigation strategies.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates