PT-2019-11503 · Marginalia · Marginalia
Published
2019-07-24
·
Updated
2019-07-29
·
CVE-2019-1010191
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
marginalia versions prior to 1.6
Description:
The issue allows for SQL Injection, enabling the injection of any SQL queries when a user controller argument is added as a component. This affects users who add components that are user-controlled, such as parameters or headers. The attack vector involves inputting SQL into a vulnerable vector, including headers or HTTP parameters.
Recommendations:
For versions prior to 1.6, update to version 1.6 to resolve the issue. As a temporary workaround, consider restricting the use of user-controlled components, such as parameters or headers, to minimize the risk of exploitation. Avoid using vulnerable vectors, including headers or HTTP parameters, until the issue is resolved.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Marginalia