OpenBMCS 2.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting arbitrary SQL code. Attackers can send GET requests to /debug/obix_test.php with malicious 'id' values to extract database information.
History

Wed, 10 Dec 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Openbmcs
Openbmcs openbmcs
Vendors & Products Openbmcs
Openbmcs openbmcs

Tue, 09 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 09 Dec 2025 20:45:00 +0000

Type Values Removed Values Added
Description OpenBMCS 2.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting arbitrary SQL code. Attackers can send GET requests to /debug/obix_test.php with malicious 'id' values to extract database information.
Title OpenBMCS SQL Injection via obix_test.php
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-12-09T20:36:54.529Z

Updated: 2025-12-09T21:34:03.251Z

Reserved: 2025-12-05T19:10:29.045Z

Link: CVE-2021-47704

cve-icon Vulnrichment

Updated: 2025-12-09T21:33:58.695Z

cve-icon NVD

Status : Received

Published: 2025-12-09T21:15:49.200

Modified: 2025-12-09T21:15:49.200

Link: CVE-2021-47704

cve-icon Redhat

No data.