PT-2014-4195 · Csp · Csp Mysql User Manager

Publicado

2014-01-15

·

Atualizado

2017-08-29

·

CVE-2014-1466

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions CSP MySQL User Manager version 2.3
Description A SQL injection issue allows remote attackers to execute arbitrary SQL commands via the login field of the "/login" API endpoint. This could potentially lead to unauthorized access or data manipulation.
Recommendations For CSP MySQL User Manager version 2.3, consider disabling the login functionality until a patch is available to prevent exploitation. Restrict access to the login page to minimize the risk of unauthorized SQL command execution.

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-1466

Produtos afetados

Csp Mysql User Manager