PT-2019-19934 · Joomla · Harmis Je Messenger

CVE-2019-9918

·

Publicado

2019-03-29

·

Atualizado

2023-02-28

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Harmis JE Messenger component version 1.2.2 for Joomla!
Description The issue allows for the execution of arbitrary SQL statements in the database due to a lack of input validation and improper query writing, making it susceptible to SQL injection.
Recommendations For Harmis JE Messenger component version 1.2.2, consider disabling the component until a patch is available to prevent SQL injection attacks. Restrict access to the database to minimize the risk of exploitation. Avoid using user-input data in queries until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-9918

Produtos afetados

Harmis Je Messenger