CVE-2018-20730: Nedi

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

A SQL injection vulnerability in NeDi before 1.7Cp3 allows any user to execute arbitrary SQL read commands via the query.php component.

Affected products

  • Nedi Nedi: up to and including 1.7c

Published 2019-01-17. Last modified 2026-06-17.