PT-2015-7276 · Freichat · Freichat

Kacper Szurek

·

Publicado

2015-08-18

·

Atualizado

2015-08-19

·

CVE-2015-6512

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions FreiChat version 9.6
Description The issue concerns a SQL injection vulnerability in the get messages function. This vulnerability allows remote attackers to execute arbitrary SQL commands via the time parameter to the "server/freichat.php" endpoint.
Recommendations For FreiChat version 9.6, consider restricting access to the get messages function in server/plugins/chatroom/chatroom.php until a patch is available. Avoid using the time parameter in the affected endpoint to minimize the risk of exploitation.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-6512

Produtos afetados

Freichat