PT-2021-10924 · Unknown · 188Jianzhan

Shu1Lop

·

Published

2021-11-02

·

Updated

2023-02-24

·

CVE-2020-23685

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions 188Jianzhan version 2.1.0
Description The issue allows attackers to execute arbitrary code and gain escalated privileges. This is achieved via the username parameter to the "login.php" endpoint.
Recommendations For 188Jianzhan version 2.1.0, consider restricting access to the "login.php" endpoint until a fix is available, and avoid using the username parameter in this endpoint to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2020-23685

Affected Products

188Jianzhan