PT-2021-10821 · Unknown · Macrob7 Macs Framework Content Management System

Published

2021-10-22

·

Updated

2021-10-29

·

CVE-2020-23045

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Macrob7 Macs Framework Content Management System version 1.14f
Description A SQL injection issue was found in the Macrob7 Macs Framework Content Management System. The issue is related to the roleId parameter in the editRole and deletUser modules.
Recommendations For Macrob7 Macs Framework Content Management System version 1.14f, consider restricting access to the editRole and deletUser modules until a patch is available. Avoid using the roleId parameter in these modules to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-23045

Affected Products

Macrob7 Macs Framework Content Management System