PT-2021-10499 · Unknown · White Shark System

Published

2021-06-21

·

Updated

2021-06-23

·

CVE-2020-20474

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: White Shark System (WSS) version 1.3.2
Description: The issue is related to a SQL injection vulnerability. It arises from the default task edituser.php files failing to properly filter the csa to user parameter. This allows remote attackers to exploit the vulnerability and obtain sensitive database information.
Recommendations: For White Shark System (WSS) version 1.3.2, as a temporary workaround, consider restricting access to the default task edituser.php file until a patch is available. Avoid using the csa to user parameter in the affected endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-20474

Affected Products

White Shark System