PT-2022-8498 · Unknown · Rukovoditel Project Management App

Published

2022-04-18

·

Updated

2022-04-26

·

CVE-2020-13590

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Rukovoditel Project Management App version 2.7.2
Description Multiple exploitable SQL injection vulnerabilities exist in the 'entities/fields' page. A specially crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger these vulnerabilities, which can be done either with administrator credentials or through cross-site request forgery.
Recommendations For version 2.7.2, consider restricting access to the 'entities/fields' page until a patch is available. As a temporary workaround, limit the ability to make authenticated HTTP requests to this page to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-13590

Affected Products

Rukovoditel Project Management App