PT-2021-9640 · Phpgacl · Phpgacl

Published

2021-01-30

·

Updated

2022-08-06

·

CVE-2020-13566

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions phpGACL version 3.3.7
Description The issue allows for SQL injection through a specially crafted HTTP request. In the file admin/edit group.php, when the POST parameter action is set to “Delete”, the POST parameter delete group can lead to a SQL injection. This can be triggered by an attacker sending a crafted HTTP request.
Recommendations For phpGACL version 3.3.7, consider disabling the delete group functionality in admin/edit group.php until a patch is available. Restrict access to the admin/edit group.php file to minimize the risk of exploitation. Avoid using the delete group parameter in the affected HTTP request until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2020-13566

Affected Products

Phpgacl