CVE-2019-8923 describes a critical SQL injection vulnerability affecting XAMPP versions through 5.6.8, specifically within the cds-fpdf.php jahr parameter. This flaw carries a CVSS score of 9.8, indicating a severe risk with a network-based attack vector, low complexity, and potential for complete compromise of confidentiality, integrity, and availability. While the product is discontinued and there is no evidence of active exploitation in the wild or Metasploit/Nuclei modules, an ExploitDB entry (EDB-46424) confirms the availability of exploit code. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.6.8CPE matchmatch criteria | cpe:2.3:a:apachefriends:xampp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.