PT-2021-9655 · Unknown · Rukovoditel Project Management App

Yuri Kramarz

·

Published

2021-08-17

·

Updated

2022-10-06

·

CVE-2020-13589

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Rukovoditel Project Management App version 2.7.2
Description The issue is related to an exploitable SQL injection vulnerability in the 'entities/fields' page. Specifically, the entities id parameter in this page is vulnerable when using the multiple edit, copy selected, or export functions. This vulnerability can be triggered by making authenticated HTTP requests, which can be achieved with administrator credentials or through cross-site request forgery.
Recommendations For Rukovoditel Project Management App version 2.7.2, consider restricting access to the 'entities/fields' page until a patch is available, and avoid using the entities id parameter in the multiple edit, copy selected, or export functions to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2020-13589

Affected Products

Rukovoditel Project Management App