PT-2020-13933 · Divebook · Divebook
Published
2020-12-08
·
Updated
2020-12-10
·
CVE-2020-14207
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
DiveBook plugin version 1.1.4
Description
The issue allows unauthenticated users to retrieve data from the database due to a SQL injection flaw within the "divelog.php" file. Specifically, the
filter diver parameter in the "divelog.php" file is vulnerable.Recommendations
For DiveBook plugin version 1.1.4, avoid using the
filter diver parameter in the "divelog.php" file until a fix is available. Consider restricting access to the "divelog.php" file to minimize the risk of exploitation.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Divebook