PT-2019-11999 · Mkcms · Mkcms

Publicado

2019-04-02

·

Atualizado

2019-04-03

·

CVE-2019-10707

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MKCMS version 5.0
Description The issue is related to SQL injection, which occurs via the play parameter in the bplay.php file.
Recommendations For MKCMS version 5.0, avoid using the play parameter in the bplay.php file until a patch is available. As a temporary workaround, consider restricting access to the bplay.php file to minimize the risk of exploitation.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-10707

Produtos afetados

Mkcms