PT-2020-7768 · Lexiglot · Lexiglot

Eldar Marcussen

·

Published

2020-06-01

·

Updated

2020-06-02

·

CVE-2014-8945

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Lexiglot versions through 2014-11-20
Description: The issue allows command injection via the username and password fields in the "admin.php?page=projects" endpoint.
Recommendations: For versions through 2014-11-20, update to a version released after 2014-11-20 to resolve the issue. As a temporary workaround, consider restricting access to the "admin.php?page=projects" endpoint until a patch is available. Avoid using the username and password fields in the affected endpoint until the issue is resolved.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-8945

Affected Products

Lexiglot