CVE-2015-10016

MEDIUM

jeff-kelley opensim-utils - SQL Injection

Title source: llm
STIX 2.1

Description

A vulnerability, which was classified as critical, has been found in jeff-kelley opensim-utils. Affected by this issue is the function DatabaseForRegion of the file regionscrits.php. The manipulation of the argument region leads to sql injection. The patch is identified as c29e5c729a833a29dbf5b1e505a0553fe154575e. It is recommended to apply a patch to fix this issue. VDB-217550 is the identifier assigned to this vulnerability.

References (3)

Core 3
Core References
Permissions Required, Third Party Advisory vdb-entry technical-description
https://vuldb.com/?id.217550
Permissions Required, Third Party Advisory signature permissions-required
https://vuldb.com/?ctiid.217550

Scores

CVSS v3 5.5
EPSS 0.0066
EPSS Percentile 47.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
opensim-utils_project/opensim-utils < 12-14-2015
Published Jan 06, 2023
Tracked Since Feb 18, 2026