PT-2023-29086 · Unknown · Codecanyon Credit Lite

Skalvin

·

Publicado

2023-08-18

·

Atualizado

2024-05-17

·

CVE-2023-4407

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Codecanyon Credit Lite version 1.5.4
Description A critical vulnerability was found in the component POST Request Handler, specifically in the file /portal/reports/account statement. The manipulation of the date1 and date2 arguments leads to SQL injection. The attack can be launched remotely.
Recommendations For Codecanyon Credit Lite version 1.5.4, consider disabling the /portal/reports/account statement endpoint until a patch is available. Restrict access to the POST Request Handler component to minimize the risk of exploitation. Avoid using the date1 and date2 arguments in the affected endpoint until the issue is resolved.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-4407

Produtos afetados

Codecanyon Credit Lite