SQL Injection in the listdomains function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to access or manipulate database contents via the arananalan POST parameter.
History

Thu, 21 Aug 2025 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-89
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 21 Aug 2025 14:45:00 +0000

Type Values Removed Values Added
Description SQL Injection in the listdomains function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to access or manipulate database contents via the arananalan POST parameter.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-08-21T00:00:00.000Z

Updated: 2025-08-21T19:55:05.344Z

Reserved: 2025-06-16T00:00:00.000Z

Link: CVE-2025-50860

cve-icon Vulnrichment

Updated: 2025-08-21T19:54:58.345Z

cve-icon NVD

Status : Received

Published: 2025-08-21T15:15:32.610

Modified: 2025-08-21T20:15:36.213

Link: CVE-2025-50860

cve-icon Redhat

No data.