PT-2017-14909 · Unknown · Freelance Website Script

Ihsan Sencan

·

Published

2017-12-13

·

Updated

2017-12-26

·

CVE-2017-17613

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Freelance Website Script version 2.0.6
Description The issue is related to SQL Injection, which can be exploited via the pr id parameter in the "jobdetails.php" endpoint or the catid parameter in the "searchbycat list.php" endpoint.
Recommendations For Freelance Website Script version 2.0.6, consider restricting access to the jobdetails.php and searchbycat list.php endpoints until a patch is available. As a temporary workaround, avoid using the pr id and catid parameters in these endpoints to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-17613

Affected Products

Freelance Website Script