CVE-2019-8923
CRITICALApachefriends Xampp < 5.6.8 - SQL Injection
Title source: ruleDescription
XAMPP through 5.6.8 and previous allows SQL injection via the cds-fpdf.php jahr parameter. NOTE: This product is discontinued.
Exploits (1)
References (7)
Scores
CVSS v3
9.8
EPSS
0.1065
EPSS Percentile
93.3%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-89
Status
published
Products (1)
apachefriends/xampp
< 5.6.8
Published
May 14, 2019
Tracked Since
Feb 18, 2026