PT-2019-14957 · Wikid · Wikid 2Fa Enterprise Server

Published

2019-10-17

·

Updated

2019-10-22

·

CVE-2019-17119

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WiKID 2FA Enterprise Server versions through 4.2.0-b2053
Description The issue allows authenticated users to execute arbitrary SQL commands via the source or subString parameter in Logs.jsp. This can lead to unauthorized data access and manipulation.
Recommendations For versions through 4.2.0-b2053, update to a version that contains a fix for this issue to prevent SQL injection attacks. As a temporary workaround, consider restricting access to the Logs.jsp page and limiting the use of the source and subString parameters until a patch is available.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-17119

Affected Products

Wikid 2Fa Enterprise Server