PT-2020-6132 · Phpzag · Phpzag

Larry W. Cashdollar

+1

·

Published

2020-05-19

·

Updated

2020-07-09

·

CVE-2020-8521

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions phpzag live add edit delete data tables records with ajax php mysql (affected versions not specified)
Description The issue is related to a lack of protection against SQL query structure exploitation, potentially allowing a remote attacker to impact the confidentiality, integrity, and availability of protected information. The vulnerability involves SQL injection with start and length parameters in Records.php.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03138
CVE-2020-8521

Affected Products

Phpzag