Impact
An unauthenticated attacker can send a specially crafted XML request to the /pa endpoint of Switchvox SMB Edition. The PhoneIP field is concatenated directly into PostgreSQL queries without any sanitization or parameterization, an example of a CWE-89 SQL injection vulnerability, allowing arbitrary SQL to be executed. This flaw can be used to run database operations and ultimately execute arbitrary code on the host, giving the attacker full control over the system.
Affected Systems
The vulnerability affects Sangoma Switchvox SMB Edition version 8.3 (build 104997). No other versions were listed as affected.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity, while the EPSS score of less than 1% suggests a low but nonzero probability of exploitation under normal circumstances. The vulnerability is not currently listed in CISA’s KEV catalog. Due to the absence of authentication required and the ability to reach the vulnerable endpoint over the network, the likely attack vector is an unauthenticated remote attacker sending crafted XML to the /pa service.
OpenCVE Enrichment