PT-2018-11469 · Hongcms · Hongcms

Hzllaga

·

Published

2018-06-27

·

Updated

2018-08-20

·

CVE-2018-12912

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HongCMS version 3.0.0
Description A SQL Injection issue was discovered in the admin/controllers/database.php file. The issue can be exploited via the "admin/index.php/database/operate?dbaction=emptytable&tablename=" URI, allowing for potential SQL injection attacks.
Recommendations For HongCMS version 3.0.0, consider restricting access to the "admin/index.php/database/operate" endpoint until a patch is available. As a temporary workaround, avoid using the tablename parameter in the affected URI to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-12912

Affected Products

Hongcms