PT-2023-10220 · Unknown · Dovgalyuk Aibattle
Dovgalyuk Ai
·
Published
2023-01-13
·
Updated
2024-08-06
·
CVE-2015-10041
CVSS v2.0
5.2
Medium
| Vector | AV:A/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Dovgalyuk AIBattle (affected versions not specified)
Description
A critical vulnerability has been found in Dovgalyuk AIBattle. The issue affects the
sendComments function of the file site/procedures.php. The manipulation of the text argument leads to SQL injection.Recommendations
Apply a patch to fix this issue. The patch is identified by the name e3aa4d0900167641d41cbccf53909229f00381c9. As a temporary workaround, consider disabling the
sendComments function until a patch is available. Restrict access to the site/procedures.php file to minimize the risk of exploitation. Avoid using the text argument in the affected function until the issue is resolved.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dovgalyuk Aibattle