PT-2020-7764 · Lexiglot · Lexiglot
Eldar Marcussen
·
Published
2020-06-01
·
Updated
2020-06-02
·
CVE-2014-8941
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Lexiglot versions prior to 2014-11-20
Description:
The issue allows SQL injection via specific URI parameters. This can be exploited through the "admin.php?page=users&from id=" or "admin.php?page=history&limit=" API endpoints, using the
from id and limit variables.Recommendations:
For versions prior to 2014-11-20, consider restricting access to the "admin.php?page=users" and "admin.php?page=history" API endpoints until a fix is available. Avoid using the
from id and limit variables in these endpoints to minimize the risk of exploitation.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lexiglot