PT-2017-19216 · Easysite · Easysite
Published
2017-06-24
·
Updated
2017-07-07
·
CVE-2017-9848
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Easysite version 7.0
Description
The issue allows remote attackers to execute arbitrary SQL commands via a crafted XML document. This is achieved by manipulating the
ArticleIDs element within the GetArticleHitsArray element in the C InfoService.asmx file, part of the WebServices component.Recommendations
For Easysite version 7.0, consider restricting access to the
C InfoService.asmx file until a patch is available. As a temporary workaround, avoid using the ArticleIDs element within the GetArticleHitsArray element in XML documents to minimize the risk of exploitation.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Easysite