PT-2022-12421 · Xbtit · Xbtit

Published

2022-03-16

·

Updated

2022-03-28

·

CVE-2021-45821

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Xbtit version 3.1
Description A blind SQL injection issue exists via the sid parameter in the "ajaxchat/getHistoryChatData.php" file, accessible by registered users. This allows malicious users to extract sensitive data, such as usernames and passwords, and potentially achieve remote code execution on the remote web server.
Recommendations For Xbtit version 3.1, consider restricting access to the "ajaxchat/getHistoryChatData.php" file or disabling the sid parameter to minimize the risk of exploitation until a patch is available.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-45821

Affected Products

Xbtit