PT-2022-12408 · Unknown · Slims 8 Akasia

Qmss

·

Published

2022-03-17

·

Updated

2022-03-23

·

CVE-2021-45791

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Slims8 Akasia version 8.3.1
Description The issue affects Slims8 Akasia, allowing SQL injection attacks through the dir parameter in several API endpoints, including "/admin/modules/bibliography/index.php", "/admin/modules/membership/member type.php", "/admin/modules/system/user group.php", and "/admin/modules/membership/index.php". This can be exploited by remotely authenticated librarian users.
Recommendations For Slims8 Akasia version 8.3.1, consider restricting access to the vulnerable API endpoints until a patch is available. As a temporary workaround, avoid using the dir parameter in the affected endpoints to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-45791

Affected Products

Slims 8 Akasia