Back

CVE-2018-4056

CRITICAL

An exploitable SQL injection vulnerability exists in the administrator web portal function of coTURN prior to version 4.5.0.9. A login message with a specially crafted username can cause an SQL injection, resulting in authentication bypass, which could give access to the TURN server administrator web portal. An attacker can log in via the external interface of the TURN server to trigger this vulnerability.

Published: Feb 5, 2019 Modified: Jun 17, 2026
CWE-89

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (3)

Vendor Product Version
coturn_project coturn * < 4.5.0.9
debian debian_linux 8.0
debian debian_linux 9.0

GitHub Security Advisory GHSA-c3pf-948r-8592

An exploitable SQL injection vulnerability exists in the administrator web portal function of...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 2.96%

Top 14% most likely to be exploited

Threat Score 40.1 / 100

Data Sources

NVD EPSS GitHub