PT-2023-10232 · Unknown · Prodigasistemas Curupira

Published

2023-01-16

·

Updated

2024-05-17

·

CVE-2015-10053

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions prodigasistemas curupira versions up to 0.1.3
Description A critical vulnerability has been found in prodigasistemas curupira, affecting an unknown function of the file app/controllers/curupira/passwords controller.rb. The manipulation leads to sql injection.
Recommendations For prodigasistemas curupira versions up to 0.1.3, upgrade to version 0.1.4 to address this issue.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-10053
GHSA-85GF-WR67-F83W

Affected Products

Prodigasistemas Curupira