PatchSiren

edirectory CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH edirectory CVE published 2026-04-05

CVE-2019-25675

CVE-2019-25675 involves multiple SQL injection vulnerabilities in eDirectory, an identity and access management solution. These vulnerabilities allow unauthenticated attackers to bypass administrator authentication and disclose sensitive files by injecting SQL code into parameters. The key parameter in the login endpoint is vulnerable to union-based SQL injection, enabling attackers to authenticate as adm [truncated]