PT-2023-10159 · Codepeople · Codepeople Cp-Polls Plugin

Published

2023-03-04

·

Updated

2024-05-17

·

CVE-2014-125091

CVSS v2.0

5.8

Medium

VectorAV:N/AC:L/Au:M/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions codepeople cp-polls Plugin version 1.0.1
Description A critical issue has been found in the codepeople cp-polls Plugin, affecting unknown code of the file cp-admin-int-message-list.inc.php. The manipulation of the lu argument leads to sql injection. The attack can be initiated remotely. Upgrading to version 1.0.2 is able to address this issue.
Recommendations For codepeople cp-polls Plugin version 1.0.1, upgrade to version 1.0.2 to address the issue. As a temporary workaround, consider restricting access to the cp-admin-int-message-list.inc.php file until the update is applied. Avoid manipulating the lu argument in the affected file to minimize the risk of exploitation.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2014-125091

Affected Products

Codepeople Cp-Polls Plugin