PT-2019-14957 · Wikid · Wikid 2Fa Enterprise Server

Publicado

2019-10-17

·

Atualizado

2019-10-22

·

CVE-2019-17119

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WiKID 2FA Enterprise Server versions through 4.2.0-b2053
Description The issue allows authenticated users to execute arbitrary SQL commands via the source or subString parameter in Logs.jsp. This can lead to unauthorized data access and manipulation.
Recommendations For versions through 4.2.0-b2053, update to a version that contains a fix for this issue to prevent SQL injection attacks. As a temporary workaround, consider restricting access to the Logs.jsp page and limiting the use of the source and subString parameters until a patch is available.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-17119

Produtos afetados

Wikid 2Fa Enterprise Server