PT-2017-15060 · Jextn · Jextn Question/Answer Extension

Ihsan Sencan

·

Published

2017-12-24

·

Updated

2019-07-01

·

CVE-2017-17871

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JEXTN Question And Answer extension version 3.1.0
Description The issue concerns SQL Injection, which can occur via the an parameter in a "view=tags" action or the ques-srch parameter.
Recommendations For JEXTN Question And Answer extension version 3.1.0, consider restricting access to the vulnerable parameters an and ques-srch to minimize the risk of exploitation. Avoid using these parameters in the affected actions until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-17871

Affected Products

Jextn Question/Answer Extension