PT-2023-14689 · Unknown · Future-Depth Institutional Management Website
Hucliluo
·
Published
2023-02-08
·
Updated
2025-03-25
·
CVE-2022-45526
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Future-Depth Institutional Management Website (IMS) version 1.0
Description
The issue allows attackers to execute arbitrary commands via the
ad parameter to "/admin area/login transfer.php" API endpoint. This enables attackers to potentially access and manipulate sensitive data.Recommendations
For Future-Depth Institutional Management Website (IMS) version 1.0, consider restricting access to the "/admin area/login transfer.php" API endpoint until a patch is available. As a temporary workaround, avoid using the
ad parameter in the affected API endpoint to minimize the risk of exploitation.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Future-Depth Institutional Management Website