PT-2022-7994 · Unknown · Kb Login Authentication Script

Ihsan Sencan

·

Published

2022-07-13

·

Updated

2022-07-20

·

CVE-2017-20127

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions KB Login Authentication Script version 1.1
Description A critical issue was found, affecting some unknown functionality. The manipulation of the username/password argument with the input 'or''=' leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Recommendations For KB Login Authentication Script version 1.1, consider temporarily restricting the use of the username and password arguments until a patch is available. As a mitigation measure, restrict access to the sql injection vulnerability to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-20127

Affected Products

Kb Login Authentication Script