PT-2018-14542 · Unknown · Advanced Comment System

Rafael Pedrero

·

Published

2018-11-29

·

Updated

2018-12-28

·

CVE-2018-18619

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Advanced Comment System version 1.0
Description The issue arises from insufficient sanitization of user-supplied data in SQL queries, specifically allowing remote attackers to execute SQL injection attacks via the "page" parameter in a URL. The product is discontinued.
Recommendations For Advanced Comment System version 1.0, as a temporary workaround, consider restricting access to the admin.php file until a resolution can be determined, and avoid using the page parameter in URLs to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-18619

Affected Products

Advanced Comment System