PT-2023-25484 · Motocms · Motocms

Publicado

2023-08-03

·

Atualizado

2023-08-08

·

CVE-2023-36213

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MotoCMS version 3.4.3
Description A SQL injection issue allows a remote attacker to gain privileges via the keyword parameter of the search function. This enables the attacker to potentially access or manipulate sensitive data.
Recommendations For MotoCMS version 3.4.3, update to a version that fixes this issue to prevent SQL injection attacks. As a temporary workaround, consider restricting access to the search function or sanitizing the keyword parameter to minimize the risk of exploitation.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-36213

Produtos afetados

Motocms