Impact
The vulnerability is a classic SQL injection in the getpwd.php script where the sip parameter is not properly sanitized. An attacker can inject arbitrary SQL statements, potentially reading, modifying or deleting data from the underlying database. The flaw is identified as CWE-74 and CWE-89.
Affected Systems
Affected versions are Raisecom Communication Command and Dispatch Management Platform prior to and including 7.6.5. The exposure originates from the getpwd.php endpoint inside the /app/users directory. No other versions or components were reported as vulnerable, but the description indicates an unknown specific file portion may be affected.
Risk and Exploitability
The CVSS score of 6.9 classifies the issue as medium‑high severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, but publicly available exploits exist and remote execution is possible. Given that the flaw exists in a web‑accessible file, an unauthenticated or low‑privilege attacker could exploit it from the Internet, making the risk non‑negligible without a patch.
OpenCVE Enrichment