PT-2021-3359 · 74Cms · 74Cms

Blindkey

·

Published

2021-06-16

·

Updated

2021-06-21

·

CVE-2020-22211

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions 74cms version 3.2.0
Description The issue is related to a lack of protection against SQL structure attacks in the plus/ajax street.php component of the 74cms system. This can be exploited by a remote attacker to execute arbitrary SQL queries via the key parameter.
Recommendations For 74cms version 3.2.0, consider restricting access to the plus/ajax street.php endpoint until a patch is available, and avoid using the key parameter in this endpoint to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03197
CVE-2020-22211

Affected Products

74Cms