Goautodial develops a modestly scoped contact-center and telephony automation platform comprising products such as Goautodial, Goadmin, and its API layer. The recurring exposure centers on input-handling and authentication weaknesses including OS command injection, SQL injection, path traversal, and authentication bypass, reflecting the integration demands and user-facing interfaces of telephony management software. Public exploit code has frequently been developed for vulnerabilities in this vendor's products; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Goautodial over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-2845HIGH The cpanel function in go_site.php in GoAutoDial GoAdmin CE before 3.3-1421902800 allows remote attackers to execute arbitrary commands via the $type portion of the PATH_INFO. | May 12, 2015 | 10.0 | 80 | NO | YES |
CVE-2015-2843HIGH Multiple SQL injection vulnerabilities in GoAutoDial GoAdmin CE before 3.3-1421902800 allow remote attackers to execute arbitrary SQL commands via the (1) user_name or (2) user_pas | May 12, 2015 | 7.5 | 57 | NO | YES |
CVE-2015-2844HIGH The cpanel function in go_site.php in GoAutoDial GoAdmin CE before 3.3-1420434000 allows remote attackers to execute arbitrary commands via the $action portion of the PATH_INFO. | May 12, 2015 | 10.0 | 41 | NO | YES |
CVE-2015-2842HIGH Unrestricted file upload vulnerability in go_audiostore.php in the audiostore (Voice Files) upload functionality in GoAutoDial GoAdmin CE 3.x before 3.3-1421902800 allows remote at | May 12, 2015 | 10.0 | 41 | NO | YES |
CVE-2021-43176HIGH The GOautodial API prior to commit 3c3a979 made on October 13th, 2021 takes a user-supplied “action” parameter and appends a .php file extension to locate and load the correct PHP | Dec 7, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-43175HIGH The GOautodial API prior to commit 3c3a979 made on October 13th, 2021 exposes an API router that accepts a username, password, and action that routes to other PHP files that implem | Dec 7, 2021 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Goautodial.
Media articles that mention a CVE ID that affects a product developed by Goautodial — matched by CVE ID, not by vendor name.