← back
CVE-2021-47704

OpenBMCS SQL Injection via obix_test.php

CVSS 8.7 HIGHEPSS 0.3%CWE-89
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.7EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
09 Dec 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
OpenBMCS 2.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting arbitrary SQL code. Attackers can send GET requests to /debug/obix_test.php with malicious 'id' values to extract database information.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Affected products
OPEN BMCS · OpenBMCS

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →