PT-2022-23501 · Yimioa · Yimioa

Uzjuo

·

Published

2022-08-19

·

Updated

2022-08-23

·

CVE-2022-36605

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Yimioa version 6.1
Description A SQL injection issue was found in Yimioa via the orderbyGET parameter. This allows for potential manipulation of database queries.
Recommendations For Yimioa version 6.1, consider restricting access to the orderbyGET parameter until a patch is available. Avoid using the orderbyGET parameter in sensitive queries to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-36605

Affected Products

Yimioa