PT-2021-10188 · Unknown · Hucart Cms

Joelister

·

Published

2021-08-26

·

Updated

2021-08-27

·

CVE-2020-18476

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Hucart CMS version 5.7.4
Description: The issue is related to a SQL Injection vulnerability. It is found in the basic information field, specifically in the avatar usd image field.
Recommendations: For Hucart CMS version 5.7.4, consider restricting access to the usd image field in the avatar section to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-18476

Affected Products

Hucart Cms