PT-2023-16927 · Sourcecodester · Employee Payslip Generator
Gab3
·
Publicado
2023-03-12
·
Atualizado
2024-05-17
·
CVE-2023-1360
CVSS v2.0
5.8
Média
| Vetor | AV:N/AC:L/Au:M/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SourceCodester Employee Payslip Generator with Sending Mail version 1.2.0
Description
A critical issue affects the processing of the file classes/Users.php?f=save in the New User Creation component. The manipulation of the
username argument leads to SQL injection. The attack can be initiated remotely.Recommendations
For version 1.2.0, consider disabling the
username argument in the affected file classes/Users.php?f=save until a patch is available. Restrict access to the New User Creation component to minimize the risk of exploitation. Avoid using the username argument in the affected API endpoint until the issue is resolved.Exploit
Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Employee Payslip Generator