PT-2017-14918 · Unknown · Online Exam Test Application Script

Ihsan Sencan

·

Publicado

2017-12-13

·

Atualizado

2017-12-26

·

CVE-2017-17622

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Online Exam Test Application Script version 1.6
Description The issue is related to SQL Injection, which occurs via the sort parameter in the "exams.php" API endpoint. This allows for potential manipulation of database queries.
Recommendations For version 1.6, consider restricting access to the exams.php endpoint or avoiding the use of the sort parameter until a fix is available. As a temporary workaround, validate and sanitize all user input to prevent malicious SQL queries.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-17622

Produtos afetados

Online Exam Test Application Script