CVE-2018-19515: Ens Webgalamb

Critical severity, CVSS 9.8. EPSS: 2.9% chance of exploitation in the next 30 days.

In Webgalamb through 7.0, system/ajax.php functionality is supposed to be available only to the administrator. However, by using one of the bgsend, atment_sddd1xGz, or xls_bgimport query parameters, most of these methods become available to unauthenticated users.

Affected products

  • Ens Webgalamb: up to and including 7.0

Published 2019-03-21. Last modified 2026-06-17.