PT-2022-7890 · Unknown · The Next Generation Of Genealogy Sitebuilding
X-Cisadane
·
Published
2022-06-05
·
Updated
2022-06-14
·
CVE-2017-20017
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
The Next Generation of Genealogy Sitebuilding versions up to 11.1.0
Description
A critical issue has been found in the processing of the file /timeline2.php, where the manipulation of the
primaryID argument leads to sql injection. The attack can be initiated remotely.Recommendations
For versions up to 11.1.0, upgrade to version 11.1.1 to address this issue. As a temporary workaround, consider restricting access to the /timeline2.php file until the upgrade is applied. Avoid using the
primaryID argument in the affected file until the issue is resolved.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
The Next Generation Of Genealogy Sitebuilding