PT-2023-10108 · Unknown · Is Projecto2
CVE-2014-125038
·
Publicado
2023-01-02
·
Atualizado
2024-05-17
CVSS v2.0
5.2
Média
| Vetor | AV:A/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
IS Projecto2 (affected versions not specified)
Description
A critical vulnerability has been found in IS Projecto2, affecting unknown code in the NewsBean.java file. The manipulation of the
date argument leads to SQL injection.Recommendations
Apply the patch aa128b2c9c9fdcbbf5ecd82c1e92103573017fe0 to fix this issue. As a temporary workaround, consider restricting the manipulation of the
date argument to minimize the risk of SQL injection exploitation.Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Is Projecto2