PT-2020-14687 · Munki · Munkireport

Edouard Schweisguth

·

Published

2020-07-23

·

Updated

2022-05-24

·

CVE-2020-15886

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MunkiReport versions prior to 3.5
Description A SQL injection issue in the reportdata module allows attackers to execute arbitrary SQL commands. This is achieved by manipulating the req parameter of the "/module/reportdata/ip" endpoint.
Recommendations For versions prior to 3.5, consider restricting access to the "/module/reportdata/ip" endpoint until a patch is available. As a temporary workaround, avoid using the req parameter in the affected endpoint to minimize the risk of exploitation. Update to version 3.5 or later to resolve the issue.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15886
GHSA-QVW9-6567-WQ78

Affected Products

Munkireport