PT-2018-13286 · Jorani · Jorani

Javier Olmedo

·

Published

2018-09-05

·

Updated

2022-07-05

·

CVE-2018-15918

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Jorani version 0.6.5
Description An issue allows a user without permissions to read and modify sensitive information from the database via the startdate or enddate parameter to leaves/validate. This is due to SQL Injection, which is error-based.
Recommendations For Jorani version 0.6.5, avoid using the startdate or enddate parameter in the leaves/validate endpoint until the issue is resolved. As a temporary workaround, consider restricting access to the database to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-15918

Affected Products

Jorani