PT-2018-12277 · Wolfsight · Wolfsight Cms

Published

2018-07-12

·

Updated

2018-09-05

·

CVE-2018-14012

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WolfSight CMS version 3.2
Description The issue allows SQL injection via the PATH INFO to the default URI.
Recommendations For WolfSight CMS version 3.2, consider restricting access to the default URI to minimize the risk of exploitation. As a temporary workaround, avoid using user-supplied input in the PATH INFO until a patch is available.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-14012

Affected Products

Wolfsight Cms