A vulnerability was found in Raisecom Communication Command and Dispatch Management Platform up to 7.6.5 and classified as critical. This affects an unknown part of the file /app/users/getpwd.php. Such manipulation of the argument sip leads to sql injection.
This vulnerability is documented as CVE-2026-19764. The attack can be executed remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.