PT-2023-10248 · Unknown · Viakondratiuk Cash-Machine

Kondratiuk

·

Published

2023-01-19

·

Updated

2024-05-17

·

CVE-2015-10069

CVSS v2.0

5.2

Medium

VectorAV:A/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions viakondratiuk cash-machine (affected versions not specified)
Description A critical issue has been found in the viakondratiuk cash-machine, affecting the is card pin at session/update failed attempts function of the machine.py file. This issue leads to SQL injection.
Recommendations To fix this issue, it is recommended to apply the patch with the name 62a6e24efdfa195b70d7df140d8287fdc38eb66d. As a temporary workaround, consider disabling the is card pin at session/update failed attempts function until the patch is applied.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2015-10069

Affected Products

Viakondratiuk Cash-Machine