PT-2022-7890 · Unknown · The Next Generation Of Genealogy Sitebuilding

X-Cisadane

·

Published

2022-06-05

·

Updated

2022-06-14

·

CVE-2017-20017

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Next Generation of Genealogy Sitebuilding versions up to 11.1.0
Description A critical issue has been found in the processing of the file /timeline2.php, where the manipulation of the primaryID argument leads to sql injection. The attack can be initiated remotely.
Recommendations For versions up to 11.1.0, upgrade to version 11.1.1 to address this issue. As a temporary workaround, consider restricting access to the /timeline2.php file until the upgrade is applied. Avoid using the primaryID argument in the affected file until the issue is resolved.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-20017

Affected Products

The Next Generation Of Genealogy Sitebuilding