PT-2018-17256 · Joomla · Jgive

Ihsan Sencan

·

Publicado

2018-02-17

·

Atualizado

2018-03-02

·

CVE-2018-5970

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: JGive version 2.0.9
Description: A SQL Injection issue exists in the JGive component for Joomla, specifically via the filter org ind type or campaign countries parameter.
Recommendations: For JGive version 2.0.9, update to a newer version that contains a fix for this issue. As a temporary workaround, consider restricting access to the vulnerable parameters filter org ind type and campaign countries to minimize the risk of exploitation.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-5970

Produtos afetados

Jgive