PT-2021-3359 · 74Cms · 74Cms
Blindkey
·
Published
2021-06-16
·
Updated
2021-06-21
·
CVE-2020-22211
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
74cms version 3.2.0
Description
The issue is related to a lack of protection against SQL structure attacks in the plus/ajax street.php component of the 74cms system. This can be exploited by a remote attacker to execute arbitrary SQL queries via the
key parameter.Recommendations
For 74cms version 3.2.0, consider restricting access to the plus/ajax street.php endpoint until a patch is available, and avoid using the
key parameter in this endpoint to minimize the risk of exploitation.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
74Cms