PT-2023-10004 · Unknown · Fanzila Webfinance
Published
2023-02-03
·
Updated
2024-05-17
·
CVE-2013-10015
CVSS v2.0
5.2
Medium
| Vector | AV:A/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
fanzila WebFinance version 0.5
Description
A critical issue has been found in the file htdocs/admin/save Contract Signer Role.php, where the manipulation of the argument
n/v leads to sql injection.Recommendations
Apply the patch identified as abad81af614a9ceef3f29ab22ca6bae517619e06 to fix this issue. As a temporary workaround, consider restricting access to the
save Contract Signer Role.php file until the patch is applied.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fanzila Webfinance