PT-2018-10254 · Phprap · Phprap

Published

2018-05-14

·

Updated

2018-06-19

·

CVE-2018-11032

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHPRAP versions 1.0.4 through 1.0.8
Description The issue is related to SQL Injection, which occurs via the search() function in the application/home/controller/project.php file.
Recommendations For PHPRAP versions 1.0.4 through 1.0.8, consider disabling the search() function in the project.php file until a patch is available. Restrict access to the project.php file to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-11032

Affected Products

Phprap