PT-2023-12270 · Jocms · Jocms

Ghost

·

Published

2023-02-03

·

Updated

2023-02-10

·

CVE-2021-36431

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions jocms version 0.8
Description The issue allows remote attackers to execute arbitrary SQL commands and view sensitive information. This is achieved via the jo json check() function in jocms/apps/mask/inc/mask.php.
Recommendations For jocms version 0.8, consider disabling the jo json check() function until a patch is available to prevent exploitation. Restrict access to the mask.php file to minimize the risk of SQL injection attacks. Avoid using the jo json check() function in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2021-36431

Affected Products

Jocms