PT-2017-13573 · Pragyan · Pragyan Cms
Lnyzx
·
Published
2017-09-19
·
Updated
2017-09-22
·
CVE-2017-14601
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Pragyan CMS version 3.0
Description
The issue is related to a Boolean-based SQL injection, which can lead to Information Disclosure. This occurs in the cms/admin.lib.php file via the
forwhat variable in the $ GET request.Recommendations
For Pragyan CMS version 3.0, consider restricting access to the cms/admin.lib.php file until a patch is available. As a temporary workaround, avoid using the
forwhat variable in the affected API endpoint to minimize the risk of exploitation.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pragyan Cms