CVE-2019-1010248: I-Doit

Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.

Synetics GmbH I-doit 1.12 and earlier is affected by: SQL Injection. The impact is: Unauthenticated mysql database access. The component is: Web login form. The attack vector is: An attacker can exploit the vulnerability by sending a malicious HTTP POST request. The fixed version is: 1.12.1.

Affected products

  • I-Doit I-Doit: up to and including 1.12

Published 2019-07-18. Last modified 2026-06-17.