Back to Database
Status published
High
CVE-2019-18866
Unauthenticated SQL injection via the username in the login mechanism...
Vulnerability Description
Unauthenticated SQL injection via the username in the login mechanism in Blaauw Remote Kiln Control through v3.00r4 allows a user to extract arbitrary data from the rkc database.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-18866
Credits & Attribution
No credits recorded in the NVD database.
More from blaauwproducts
View All →CVE-2019-18872
Weak password requirements in Blaauw Remote Kiln Control through v3.00r4...
High
7.5
CVE-2019-18871
A path traversal in debug.php accessed via default.php in Blaauw...
High
8.8
CVE-2019-18870
A path traversal via the iniFile parameter in excel.php in...
Medium
6.5
CVE-2019-18869
Leftover Debug Code in Blaauw Remote Kiln Control through v3.00r4...
Critical
9.8
CVE-2019-18868
Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker...
Critical
9.8
Affected Vendor
blaauwproducts
View all reports →Affected Software
remote kiln control
Vulnerable Versions:
3.0.0, 0
Timeline
Official Publish:
May 7th, 2020
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.