PT-2019-8921 · Yeswiki · Yeswiki Cercopitheque

Ark1Nar

+1

·

Published

2019-01-02

·

Updated

2019-01-09

·

CVE-2018-13045

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Yeswiki Cercopitheque versions 2018-06-19-1 and earlier
Description The issue allows attackers to execute arbitrary SQL commands via the id parameter in the "Bazar" page. This enables unauthorized access and manipulation of database content.
Recommendations For versions 2018-06-19-1 and earlier, as a temporary workaround, consider restricting access to the "Bazar" page until a patch is available. Avoid using the id parameter in the affected page to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-13045

Affected Products

Yeswiki Cercopitheque