PT-2020-7764 · Lexiglot · Lexiglot

Eldar Marcussen

·

Published

2020-06-01

·

Updated

2020-06-02

·

CVE-2014-8941

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Lexiglot versions prior to 2014-11-20
Description: The issue allows SQL injection via specific URI parameters. This can be exploited through the "admin.php?page=users&from id=" or "admin.php?page=history&limit=" API endpoints, using the from id and limit variables.
Recommendations: For versions prior to 2014-11-20, consider restricting access to the "admin.php?page=users" and "admin.php?page=history" API endpoints until a fix is available. Avoid using the from id and limit variables in these endpoints to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-8941

Affected Products

Lexiglot