Описание
SQL Injection was discovered in adm_program/modules/dates/dates_function.php in Admidio 3.2.5. The POST parameter dat_cat_id is concatenated into a SQL query without any input validation/sanitization.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:admidio:admidio:3.2.5:*:*:*:*:*:*:*
EPSS
Процентиль: 64%
0.00471
Низкий
7.2 High
CVSS3
9 Critical
CVSS2
Дефекты
CWE-89
Связанные уязвимости
CVSS3: 7.2
github
больше 3 лет назад
SQL Injection was discovered in adm_program/modules/dates/dates_function.php in Admidio 3.2.5. The POST parameter dat_cat_id is concatenated into a SQL query without any input validation/sanitization.
EPSS
Процентиль: 64%
0.00471
Низкий
7.2 High
CVSS3
9 Critical
CVSS2
Дефекты
CWE-89