CVE-2018-16659: Rausoft Id.prove
Critical severity, CVSS 9.8. EPSS: 2.7% chance of exploitation in the next 30 days.
An issue was discovered in Rausoft ID.prove 2.95. The login page allows SQL injection via Microsoft SQL Server stacked queries in the Username POST parameter. Hypothetically, an attacker can utilize master..xp_cmdshell for the further privilege elevation.
Affected products
- Rausoft Id.prove: version 2.95 only
Published 2018-09-28. Last modified 2026-06-17.