PT-2017-11014 · Unknown · Add-Edit-Delete-Listing-For-Member-Module
Larry W. Cashdollar
+1
·
Publicado
2017-09-14
·
Atualizado
2017-09-21
·
CVE-2017-1002025
CVSS v3.1
7.2
Alta
| Vetor | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
add-edit-delete-listing-for-member-module version 1.0
Description
The issue arises from the plugin author's failure to sanitize user-supplied input via the
$act variable before passing it into an SQL statement, potentially leading to SQL injection.Recommendations
For version 1.0, ensure proper sanitization of user input, specifically the
$act variable, before it is used in SQL statements to prevent injection attacks. Consider validating and escaping user input to minimize the risk of exploitation.Exploit
Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Add-Edit-Delete-Listing-For-Member-Module