Описание
NukeViet SQL Injection vulnerability
SQL Injection vulnerability in NukeViet CMS module Shops 4.0.29 and 4.3 via the (1) listid parameter in detail.php and the (2) group_price or groupid parameters in search_result.php.
Fix Implementation:
Download the update package corresponding to the NukeViet version you are using, extract and upload to hosting according to NukeViet's structure: For NukeViet 4.0 Official (4.0.29) For NukeViet 4.1 Official (4.1.02) For NukeViet 4.2 (4.2.01) As for NukeViet 4.3, you can update according to the notice in the admin page or see here: https://nukeviet.vn/vi/news/Tin-tuc/thong-bao-phat-hanh-nukeviet-4- 3-08-613.html
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2020-21809
- https://github.com/nukeviet/module-shops/commit/742c0e0f74364f7250c2a69f0a957d4e6317be68
- https://nukeviet.vn/vi/news/Tin-an-ninh/huong-dan-fix-loi-bao-mat-nukeviet-4-va-module-shops-612.html
- https://whitehub.net/submissions/1517
- https://whitehub.net/submissions/1518
Пакеты
nukeviet/nukeviet
>= 4.0, < 4.0.29
4.0.29
nukeviet/nukeviet
>= 4.1, < 4.1.02
4.1.02
nukeviet/nukeviet
>= 4.2, < 4.2.01
4.2.01
nukeviet/nukeviet
= 4.3
Отсутствует
Связанные уязвимости
SQL Injection vulnerability in NukeViet CMS module Shops 4.0.29 and 4.3 via the (1) listid parameter in detail.php and the (2) group_price or groupid parameters in search_result.php.
Уязвимость модуля Shops системы управления контентом NukeViet, позволяющая нарушителю выполнить произвольный SQL-код