Domoticz before 4.10578 allows SQL Injection via the idx parameter in CWebServer::GetFloorplanImage in WebServer.cpp.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:a:domoticz:domoticz:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"fixed": "4.10578"
}
],
"source": "CPE_RANGE",
"vendor_product": "domoticz:domoticz"
},
{
"extracted_events": [
{
"fixed": "4.10578"
}
],
"source": "DESCRIPTION"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-10664.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"333243892252235476131594598534548326044",
"55182103125081366379743183530712515141",
"89817755638787296391356924653673538008",
"111537228598959169391174691343612986451"
],
"threshold": 0.9
},
"id": "CVE-2019-10664-0af040af",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/domoticz/domoticz/commit/ee70db46f81afa582c96b887b73bcd2a86feda00",
"target": {
"file": "main/WebServer.cpp"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "80112972407389721822115560499089427272",
"length": 824
},
"id": "CVE-2019-10664-a4a49470",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/domoticz/domoticz/commit/ee70db46f81afa582c96b887b73bcd2a86feda00",
"target": {
"file": "main/WebServer.cpp",
"function": "CWebServer::GetFloorplanImage"
}
}
]
"2026-07-08T23:59:03Z"