PT-2023-1573 · Unknown · Gimmie Plugin

CVE-2014-125084

·

Publicado

2023-02-05

·

Atualizado

2024-05-17

CVSS v2.0

5.2

Média

VetorAV:A/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Gimmie Plugin version 1.2.2
Description The issue is related to a lack of protection in the SQL query structure, which can be exploited to execute arbitrary SQL queries. This is a critical vulnerability that affects the processing of the file trigger referral.php, where the manipulation of the referrername argument leads to SQL injection.
Recommendations For Gimmie Plugin version 1.2.2, upgrade to version 1.3.0 to address this issue. As a temporary workaround, consider restricting access to the trigger referral.php file until the upgrade is applied. Additionally, avoid using the referrername argument in the affected file to minimize the risk of exploitation.

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-01041
CVE-2014-125084

Produtos afetados

Gimmie Plugin