Voipmonitor is a VoIP monitoring and analytics platform whose observed vulnerability surface concentrates on web-application input handling and authentication mechanisms, with recurring issues in SQL injection, code injection, improper authentication, and unrestricted file upload. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Voipmonitor over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24260CRITICAL A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administrator level. | Feb 4, 2022 | 9.8 | 62 | NO | YES |
CVE-2021-30461CRITICAL A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used, the user-supplied SPOOLDIR value (which might contain PHP c | May 29, 2021 | 9.8 | 62 | NO | YES |
CVE-2022-24259CRITICAL An incorrect check in the component cdr.php of Voipmonitor GUI before v24.96 allows unauthenticated attackers to escalate privileges via a crafted request. | Feb 4, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-41408CRITICAL VoIPmonitor WEB GUI up to version 24.61 is affected by SQL injection through the "api.php" file and "user" parameter. | Jun 17, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-24262HIGH The config restore function of Voipmonitor GUI before v24.96 does not properly check files sent as restore archives, allowing remote attackers to execute arbitrary commands via a c | Feb 4, 2022 | 8.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Voipmonitor.
Media articles that mention a CVE ID that affects a product developed by Voipmonitor — matched by CVE ID, not by vendor name.