{"id":"CVE-2019-10664","details":"Domoticz before 4.10578 allows SQL Injection via the idx parameter in CWebServer::GetFloorplanImage in WebServer.cpp.","modified":"2026-07-08T23:59:03.668193Z","published":"2019-03-31T14:29:00.207Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"fixed":"4.10578"}],"source":"CPE_RANGE","vendor_product":"domoticz:domoticz","cpes":["cpe:2.3:a:domoticz:domoticz:*:*:*:*:*:*:*:*"]},{"extracted_events":[{"fixed":"4.10578"}],"source":"DESCRIPTION"}]},"references":[{"type":"ADVISORY","url":"http://packetstormsecurity.com/files/152678/Domoticz-4.10577-Unauthenticated-Remote-Command-Execution.html"},{"type":"ADVISORY","url":"https://www.exploit-db.com/exploits/46773/"},{"type":"FIX","url":"https://github.com/domoticz/domoticz/commit/ee70db46f81afa582c96b887b73bcd2a86feda00"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/domoticz/domoticz","events":[{"introduced":"0"},{"fixed":"ee70db46f81afa582c96b887b73bcd2a86feda00"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-10664.json","vanir_signatures_modified":"2026-07-08T23:59:03Z","vanir_signatures":[{"target":{"file":"main/WebServer.cpp"},"deprecated":false,"digest":{"line_hashes":["333243892252235476131594598534548326044","55182103125081366379743183530712515141","89817755638787296391356924653673538008","111537228598959169391174691343612986451"],"threshold":0.9},"id":"CVE-2019-10664-0af040af","signature_type":"Line","signature_version":"v1","source":"https://github.com/domoticz/domoticz/commit/ee70db46f81afa582c96b887b73bcd2a86feda00"},{"deprecated":false,"digest":{"function_hash":"80112972407389721822115560499089427272","length":824},"id":"CVE-2019-10664-a4a49470","signature_type":"Function","signature_version":"v1","source":"https://github.com/domoticz/domoticz/commit/ee70db46f81afa582c96b887b73bcd2a86feda00","target":{"file":"main/WebServer.cpp","function":"CWebServer::GetFloorplanImage"}}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}