CVE-2015-8298 describes multiple critical SQL injection vulnerabilities in RXTEC RXAdmin UPDATE 06 / 2012. These flaws allow remote attackers to execute arbitrary SQL commands through various parameters on the login page (loginpassword, loginusername, zusatzlicher, groupid) or via the rxtec cookie to index.htm. With a CVSS score of 9.8 (CRITICAL), successful exploitation requires no user interaction or authentication and can lead to full compromise of confidentiality, integrity, and availability. Despite its high severity, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it has not been added to CISA's KEV catalog, indicating no known active exploitation. Community discussion and media coverage for this vulnerability are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2012CPE matchmatch criteria | cpe:2.3:a:rxtec:rxadmin:2012:06:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.