
CVE-2019-25580 ownDMS 4.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the IMG … https://www.cve.org/CVERecord?id=CVE-2019-25580
Post summary
The post discloses an SQL injection flaw in ownDMS 4.7 that lets unauthenticated users run arbitrary SQL via the IMG input, with no evidence of exploitation or patches.


