CVE-2020-15886: Reportdata Project Reportdata

High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.

A SQL injection vulnerability in reportdata_controller.php in the reportdata module before 3.5 for MunkiReport allows attackers to execute arbitrary SQL commands via the req parameter of the /module/reportdata/ip endpoint.

Affected products

Published 2020-07-23. Last modified 2026-06-17.