PT-2015-7276 · Freichat · Freichat

Kacper Szurek

·

Published

2015-08-18

·

Updated

2015-08-19

·

CVE-2015-6512

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions FreiChat version 9.6
Description The issue concerns a SQL injection vulnerability in the get messages function. This vulnerability allows remote attackers to execute arbitrary SQL commands via the time parameter to the "server/freichat.php" endpoint.
Recommendations For FreiChat version 9.6, consider restricting access to the get messages function in server/plugins/chatroom/chatroom.php until a patch is available. Avoid using the time parameter in the affected endpoint to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-6512

Affected Products

Freichat