PT-2017-14321 · Unknown · Mailing List Manager Pro

Ihsan Sencan

·

Published

2017-10-29

·

Updated

2017-11-17

·

CVE-2017-15967

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mailing List Manager Pro version 3.0
Description The issue allows SQL Injection via the edit parameter to admin/users in a sort=login action, or the edit parameter to admin/template.
Recommendations For Mailing List Manager Pro version 3.0, consider restricting access to the admin/users and admin/template endpoints to minimize the risk of exploitation. Avoid using the edit parameter in these endpoints until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-15967

Affected Products

Mailing List Manager Pro