PT-2018-17094 · Icy Phoenix Team · Icy Phoenix
Benjamin Kunz Mejri
·
Published
2018-01-14
·
Updated
2018-02-01
·
CVE-2018-5697
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Icy Phoenix version 2.2.0.105
Description:
The issue allows SQL injection via an unapprove request to "admin kb art.php" or the
order parameter to "admin jr admin.php", related to "functions kb.php".Recommendations:
For Icy Phoenix version 2.2.0.105, consider restricting access to the "admin kb art.php" and "admin jr admin.php" files until a patch is available, and avoid using the
order parameter in the "admin jr admin.php" endpoint to minimize the risk of exploitation.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Icy Phoenix