PT-2020-15257 · Weiphp · Weiphp

Published

2020-12-18

·

Updated

2020-12-22

·

CVE-2020-20300

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WeiPHP version 5.0
Description The issue is related to a SQL injection vulnerability in the wp where function. This vulnerability may allow attackers to inject malicious SQL code, potentially leading to unauthorized access or modification of data.
Recommendations For WeiPHP version 5.0, consider disabling the wp where function until a patch is available to prevent potential SQL injection attacks. Restrict access to sensitive data and monitor database activity closely to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-20300

Affected Products

Weiphp