PT-2026-23687 · Unknown · Alienor Web Libre
CVE-2018-25175
·
Publicado
2026-03-06
·
Atualizado
2026-03-06
CVSS v3.1
8.2
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Alienor Web Libre version 2.0
Description
Alienor Web Libre 2.0 contains an SQL injection issue that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can submit crafted POST requests to the ''index.php'' endpoint with SQL injection payloads through the
identifiant parameter. This allows extraction of sensitive database information, including usernames, databases, and version details.Recommendations
Apply a fix to sanitize the
identifiant parameter in the ''index.php'' endpoint to prevent SQL injection attacks.Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alienor Web Libre