PT-2018-13286 · Jorani · Jorani

Javier Olmedo

·

Publicado

2018-09-05

·

Atualizado

2022-07-05

·

CVE-2018-15918

CVSS v2.0

5.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Jorani version 0.6.5
Description An issue allows a user without permissions to read and modify sensitive information from the database via the startdate or enddate parameter to leaves/validate. This is due to SQL Injection, which is error-based.
Recommendations For Jorani version 0.6.5, avoid using the startdate or enddate parameter in the leaves/validate endpoint until the issue is resolved. As a temporary workaround, consider restricting access to the database to minimize the risk of exploitation.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-15918

Produtos afetados

Jorani