PT-2023-10137 · Unknown · Corincerami Curiosity

Published

2023-01-08

·

Updated

2024-05-17

·

CVE-2014-125067

CVSS v2.0

5.2

Medium

VectorAV:A/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions corincerami curiosity (affected versions not specified)
Description A critical vulnerability was found in corincerami curiosity, affecting an unknown functionality of the file app/controllers/image controller.rb. The manipulation of the sol argument leads to SQL injection.
Recommendations Apply a patch named d64fddd74ca72714e73f4efe24259ca05c8190eb to fix this issue. As a temporary workaround, consider restricting the manipulation of the sol argument to minimize the risk of SQL injection exploitation.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2014-125067

Affected Products

Corincerami Curiosity