PT-2023-10137 · Unknown · Corincerami Curiosity
Published
2023-01-08
·
Updated
2024-05-17
·
CVE-2014-125067
CVSS v2.0
5.2
Medium
| Vector | AV:A/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
corincerami curiosity (affected versions not specified)
Description
A critical vulnerability was found in corincerami curiosity, affecting an unknown functionality of the file app/controllers/image controller.rb. The manipulation of the
sol argument leads to SQL injection.Recommendations
Apply a patch named d64fddd74ca72714e73f4efe24259ca05c8190eb to fix this issue. As a temporary workaround, consider restricting the manipulation of the
sol argument to minimize the risk of SQL injection exploitation.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Corincerami Curiosity