CVE-2018-11643: Dialogic Powermedia Xms

High severity, CVSS 8.8. EPSS: 1.4% chance of exploitation in the next 30 days.

SQL injection vulnerability in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote authenticated users to execute arbitrary SQL commands via the filterPattern parameter.

Affected products

  • Dialogic Powermedia Xms: up to and including 3.5

Published 2018-07-03. Last modified 2026-06-17.