ResourceSpace 8.6 SQL Injection via collection_edit.php
Published Apr 12, 2026
7.1
HIGHCVSS 4.0
EPSS 0.16%
Description
ResourceSpace 8.6 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the keywords parameter in collection_edit.php. Attackers can submit POST requests with crafted SQL payloads in the keywords field to extract sensitive database information including schema names, user credentials, and other confidential data.
Affected products
-
Affected
- Stable release: 8.6
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Resourcespace | ResourceSpace | unknown | Affected
|
- 8.6
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-20128 Advisory
- https://www.exploit-db.com/exploits/46274 exploitVDB Entry
- https://www.resourcespace.com/ product
- https://www.resourcespace.com/get product
- https://www.vulncheck.com/advisories/resourcespace-sql-injection-via-collection-edit-php third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-20128 | Advisory | |
| https://www.exploit-db.com/exploits/46274 | exploitVDB Entry | |
| https://www.resourcespace.com/ | product | |
| https://www.resourcespace.com/get | product | |
| https://www.vulncheck.com/advisories/resourcespace-sql-injection-via-collection-edit-php | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data