PT-2020-6133 · Phpzag · Phpzag

Larry W. Cashdollar

+1

·

Published

2020-05-19

·

Updated

2020-07-09

·

CVE-2020-8519

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions phpzag live add edit delete data tables records with ajax php mysql (affected versions not specified)
Description The issue is related to a lack of protection against SQL query structure exploitation, potentially allowing a remote attacker to impact the confidentiality, integrity, and availability of protected information. The vulnerability involves SQL injection with the search parameter in Records.php.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03139
CVE-2020-8519

Affected Products

Phpzag