CVE-2015-2843: Goautodial Goadmin CE

High severity, CVSS 7.5. EPSS: 37.9% chance of exploitation in the next 30 days.

Multiple SQL injection vulnerabilities in GoAutoDial GoAdmin CE before 3.3-1421902800 allow remote attackers to execute arbitrary SQL commands via the (1) user_name or (2) user_pass parameter in go_login.php or the PATH_INFO to (3) go_login/validate_credentials/admin/ or (4) index.php/go_site/go_get_user_info/.

Affected products

  • Goautodial Goadmin CE: version 3.0 only; version 3.3 only

Published 2015-05-12. Last modified 2026-06-17.