PT-2018-13286 · Jorani · Jorani
Javier Olmedo
·
Publicado
2018-09-05
·
Atualizado
2022-07-05
·
CVE-2018-15918
CVSS v2.0
5.5
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Jorani version 0.6.5
Description
An issue allows a user without permissions to read and modify sensitive information from the database via the
startdate or enddate parameter to leaves/validate. This is due to SQL Injection, which is error-based.Recommendations
For Jorani version 0.6.5, avoid using the
startdate or enddate parameter in the leaves/validate endpoint until the issue is resolved. As a temporary workaround, consider restricting access to the database to minimize the risk of exploitation.Exploit
Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Jorani