PT-2012-5926 · Mingle · Mingle Forum

Published

2012-10-08

·

Updated

2017-08-29

·

CVE-2012-5327

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Mingle Forum plugin versions 1.0.32.1 and prior to 1.0.33
Description The issue allows remote authenticated users to execute arbitrary SQL commands. This can be achieved via the delete usrgrp[] parameter in a "delete usergroups" action, the usergroup parameter in an "add user togroup" action, or the add forum group id parameter in an "add forum submit" action.
Recommendations For versions 1.0.32.1 and prior to 1.0.33, update to version 1.0.33 or later to resolve the issue.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-5327

Affected Products

Mingle Forum