PT-2022-12421 · Xbtit · Xbtit
Published
2022-03-16
·
Updated
2022-03-28
·
CVE-2021-45821
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Xbtit version 3.1
Description
A blind SQL injection issue exists via the
sid parameter in the "ajaxchat/getHistoryChatData.php" file, accessible by registered users. This allows malicious users to extract sensitive data, such as usernames and passwords, and potentially achieve remote code execution on the remote web server.Recommendations
For Xbtit version 3.1, consider restricting access to the "ajaxchat/getHistoryChatData.php" file or disabling the
sid parameter to minimize the risk of exploitation until a patch is available.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xbtit