PT-2021-15558 · Flatcore · Flatcore

Published

2021-01-15

·

Updated

2021-01-22

·

CVE-2021-23837

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: flatCore versions prior to 2.0.0 build 139
Description: A time-based blind SQL injection issue was identified in the selected folder HTTP request body parameter for the acp interface. This parameter, which retrieves the file contents of the specified folder, was found to be accepting malicious user input without proper sanitization, leading to SQL injection. As a result, database-related information can be successfully retrieved.
Recommendations: For versions prior to 2.0.0 build 139, consider disabling the selected folder parameter in the acp interface until a patch is available. Restrict access to the acp interface to minimize the risk of exploitation. Avoid using the selected folder parameter in the affected HTTP request body until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-23837

Affected Products

Flatcore