PT-2023-11818 · Unknown · Pouetnet Pouet
CVE-2020-36648
·
Publicado
2023-01-08
·
Atualizado
2024-05-17
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
pouetnet pouet version 2.0
Description
A critical issue was found in pouetnet pouet, affecting an unknown part. The manipulation of the
howmany argument leads to SQL injection.Recommendations
For pouetnet pouet version 2.0, it is recommended to apply a patch to fix this issue. As a temporary workaround, consider restricting the manipulation of the
howmany argument to minimize the risk of SQL injection exploitation.Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Pouetnet Pouet