PT-2019-17492 · Youphptube · Youphptube

Published

2019-10-25

·

Updated

2022-06-27

·

CVE-2019-5123

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions YouPHPTube version 7.6
Description The issue allows specially crafted web requests to cause SQL injections. An attacker can exploit this by sending a web request with the dir parameter in the "/objects/pluginSwitch.json.php" endpoint.
Recommendations For YouPHPTube version 7.6, consider restricting access to the "/objects/pluginSwitch.json.php" endpoint until a patch is available. As a temporary workaround, avoid using the dir parameter in this endpoint to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-5123

Affected Products

Youphptube