PT-2021-9641 · Phpgacl · Phpgacl

Claudio Bozzato

·

Published

2021-01-30

·

Updated

2022-08-06

·

CVE-2020-13568

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions phpGACL version 3.3.7
Description A SQL injection issue exists, allowing an attacker to send a specially crafted HTTP request to trigger the issue in admin/edit group.php. When the POST parameter action is “Submit”, the POST parameter parent id can lead to a SQL injection.
Recommendations For phpGACL version 3.3.7, as a temporary workaround, consider restricting access to the admin/edit group.php endpoint until a patch is available. Avoid using the parent id parameter in the affected endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2020-13568

Affected Products

Phpgacl