PT-2023-11818 · Unknown · Pouetnet Pouet
Published
2023-01-08
·
Updated
2024-05-17
·
CVE-2020-36648
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
pouetnet pouet version 2.0
Description
A critical issue was found in pouetnet pouet, affecting an unknown part. The manipulation of the
howmany argument leads to SQL injection.Recommendations
For pouetnet pouet version 2.0, it is recommended to apply a patch to fix this issue. As a temporary workaround, consider restricting the manipulation of the
howmany argument to minimize the risk of SQL injection exploitation.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pouetnet Pouet