PT-2020-15885 · Heybbs · Heybbs

Published

2020-09-03

·

Updated

2020-09-04

·

CVE-2020-25006

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Heybbs version 1.2
Description The issue is related to a SQL injection vulnerability in the login.php file, specifically via the username parameter. This may allow a remote attacker to execute arbitrary code.
Recommendations For Heybbs version 1.2, consider restricting access to the login.php file or avoiding the use of the username parameter until a fix is available. As a temporary workaround, disabling the login functionality that utilizes the vulnerable username parameter may help minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-25006

Affected Products

Heybbs