What is CVE-2026-19764?
A SQL injection vulnerability was found in Raisecom Communication Command and Dispatch Management Platform up to version 7.6.5, affecting the `/app/users/getpwd.php` file. The vulnerability can be exploited remotely by manipulating the `sip` argument, allowing unauthorized database access. Users should apply the vendor's security update immediately.
Azərbaycanca: Raisecom Communication Command and Dispatch Management Platform-un 7.6.5 versiyasına qədər olan versiyalarında `/app/users/getpwd.php` faylında SQL inyeksiya zəifliyi aşkarlanıb. Bu zəiflik uzaqdan istismar edilə bilər və `sip` parametri vasitəsilə məlumat bazasına müdaxiləyə imkan yaradır. İstifadəçilər istehsalçının təhlükəsizlik yeniləməsini tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which versions of Raisecom Communication Command and Dispatch Management Platform are affected by CVE-2026-19764?
The vulnerability affects all versions up to 7.6.5.
Which parameter is targeted to exploit CVE-2026-19764?
The vulnerability can be exploited via the `sip` parameter in the `/app/users/getpwd.php` file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.