Grandstream UCM6200 series contains an unauthenticated remote SQL injection caused by crafted HTTP requests, letting attackers execute shell commands as root on versions before 1.0.19.20 or inject HTML in emails before 1.0.20.17.
id: CVE-2020-5722
info:
name: Grandstream UCM6200 - SQL Injection
author: theamanrawat
severi
...