PT-2019-14955 · Wikid · Wikid 2Fa Enterprise Server

Published

2019-10-17

·

Updated

2019-10-22

·

CVE-2019-17117

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WiKID 2FA Enterprise Server versions through 4.2.0-b2053
Description A SQL injection issue allows an authenticated user to execute arbitrary SQL commands via the key parameter in the processPref.jsp file.
Recommendations For versions through 4.2.0-b2053, consider restricting access to the processPref.jsp file until a patch is available. As a temporary workaround, avoid using the key parameter in the processPref.jsp file to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-17117

Affected Products

Wikid 2Fa Enterprise Server