PT-2023-10248 · Unknown · Viakondratiuk Cash-Machine

Kondratiuk

·

Publicado

2023-01-19

·

Atualizado

2024-05-17

·

CVE-2015-10069

CVSS v2.0

5.2

Média

VetorAV:A/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions viakondratiuk cash-machine (affected versions not specified)
Description A critical issue has been found in the viakondratiuk cash-machine, affecting the is card pin at session/update failed attempts function of the machine.py file. This issue leads to SQL injection.
Recommendations To fix this issue, it is recommended to apply the patch with the name 62a6e24efdfa195b70d7df140d8287fdc38eb66d. As a temporary workaround, consider disabling the is card pin at session/update failed attempts function until the patch is applied.

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-10069

Produtos afetados

Viakondratiuk Cash-Machine