PT-2018-15003 · Arcms · Arcms

Published

2018-11-26

·

Updated

2018-12-19

·

CVE-2018-19558

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions arcms through 2018-03-19
Description An issue exists in the software due to SQL injection via the limit parameter in the json/newslist endpoint. This is caused by files ctl/main/Json.php, ctl/main/service/Data.php, and comp/Db/Mysql.php.
Recommendations For arcms through 2018-03-19, as a temporary workaround, consider restricting access to the json/newslist endpoint until a patch is available. Avoid using the limit parameter in this endpoint to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-19558

Affected Products

Arcms