CVE-2019-1010248
CVE-2019-1010248 is a critical-severity vulnerability in I-doit with a CVSS 3.x base score of 9.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-89.
Key facts
- Severity: Critical (CVSS 3.x base score 9.8)
- CVSS v2: 7.5
- EPSS exploit prediction: 1% (71st percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-89
- Affected product: I-doit
- Published:
- Last modified:
Description
Synetics GmbH I-doit 1.12 and earlier is affected by: SQL Injection. The impact is: Unauthenticated mysql database access. The component is: Web login form. The attack vector is: An attacker can exploit the vulnerability by sending a malicious HTTP POST request. The fixed version is: 1.12.1.
Frequently asked questions
- What is CVE-2019-1010248?
- Synetics GmbH I-doit 1.12 and earlier is affected by: SQL Injection. The impact is: Unauthenticated mysql database access. The component is: Web login form. The attack vector is: An attacker can exploit the vulnerability by sending a malicious HTTP POST request. The fixed version is: 1.12.1.
- How severe is CVE-2019-1010248?
- CVE-2019-1010248 has a CVSS 3.x base score of 9.8, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2019-1010248 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (71st percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2019-1010248?
- CVE-2019-1010248 affects I-doit. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2019-1010248?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2019-1010248 published?
- CVE-2019-1010248 was published on 2019-07-18 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:i-doit:i-doit:*:*:*:*:*:*:*:*
More vulnerabilities in I-doit
- CVE-2023-37756 — Critical (CVSS 9.8): I-doit pro 25 and below and I-doit open 25 and below employ weak password requirements for Administrator account…
- CVE-2023-37755 — Critical (CVSS 9.8): i-doit pro 25 and below and I-doit open 25 and below are configured with insecure default administrator credentials,…
- CVE-2024-8749 — High (CVSS 8.8): SQL injection vulnerability in idoit pro version 28. This vulnerability could allow an attacker to send a specially…
- CVE-2020-13826 — High (CVSS 8.8): A CSV injection (aka Excel Macro Injection or Formula Injection) issue in i-doit 1.14.2 allows an attacker to execute…
- CVE-2019-25581 — High (CVSS 8.2): i-doit CMDB 1.12 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL…
- CVE-2014-1597 — High (CVSS 7.5): SQL injection vulnerability in the CMDB web application in synetics i-doit pro before 1.2.5 and i-doit open allows…
Other CWE-89 (SQL Injection) vulnerabilities
- CVE-2026-20030 — Critical (CVSS 10.0): As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team…
- CVE-2026-72811 — Critical (CVSS 10.0): SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query…
- CVE-2026-72851 — Critical (CVSS 10.0): Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with…
- CVE-2026-72899 — Critical (CVSS 10.0): Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that…
- CVE-2026-72898 — Critical (CVSS 10.0): Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint…
- CVE-2026-48330 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL…