PT-2023-10220 · Unknown · Dovgalyuk Aibattle

Dovgalyuk Ai

·

Published

2023-01-13

·

Updated

2024-08-06

·

CVE-2015-10041

CVSS v2.0

5.2

Medium

VectorAV:A/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Dovgalyuk AIBattle (affected versions not specified)
Description A critical vulnerability has been found in Dovgalyuk AIBattle. The issue affects the sendComments function of the file site/procedures.php. The manipulation of the text argument leads to SQL injection.
Recommendations Apply a patch to fix this issue. The patch is identified by the name e3aa4d0900167641d41cbccf53909229f00381c9. As a temporary workaround, consider disabling the sendComments function until a patch is available. Restrict access to the site/procedures.php file to minimize the risk of exploitation. Avoid using the text argument in the affected function until the issue is resolved.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2015-10041

Affected Products

Dovgalyuk Aibattle