PT-2019-8921 · Yeswiki · Yeswiki Cercopitheque

Ark1Nar

+1

·

Publicado

2019-01-02

·

Atualizado

2019-01-09

·

CVE-2018-13045

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Yeswiki Cercopitheque versions 2018-06-19-1 and earlier
Description The issue allows attackers to execute arbitrary SQL commands via the id parameter in the "Bazar" page. This enables unauthorized access and manipulation of database content.
Recommendations For versions 2018-06-19-1 and earlier, as a temporary workaround, consider restricting access to the "Bazar" page until a patch is available. Avoid using the id parameter in the affected page to minimize the risk of exploitation.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-13045

Produtos afetados

Yeswiki Cercopitheque