PT-2020-15883 · Heybbs · Heybbs

Published

2020-09-03

·

Updated

2020-09-04

·

CVE-2020-25004

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Heybbs version 1.2
Description The issue is related to a SQL injection vulnerability in the user.php file, specifically via the ID parameter. This may allow a remote attacker to execute arbitrary code.
Recommendations For Heybbs version 1.2, consider restricting access to the ID parameter in the user.php file until a patch is available. As a temporary workaround, avoid using the ID parameter in the affected file to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-25004

Affected Products

Heybbs