PT-2023-29086 · Unknown · Codecanyon Credit Lite

Skalvin

·

Published

2023-08-18

·

Updated

2024-05-17

·

CVE-2023-4407

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Codecanyon Credit Lite version 1.5.4
Description A critical vulnerability was found in the component POST Request Handler, specifically in the file /portal/reports/account statement. The manipulation of the date1 and date2 arguments leads to SQL injection. The attack can be launched remotely.
Recommendations For Codecanyon Credit Lite version 1.5.4, consider disabling the /portal/reports/account statement endpoint until a patch is available. Restrict access to the POST Request Handler component to minimize the risk of exploitation. Avoid using the date1 and date2 arguments in the affected endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2023-4407

Affected Products

Codecanyon Credit Lite