PT-2022-27686 · Unknown · Luckyshot Crmx
CVE-2022-4592
·
Published
2022-12-18
·
Updated
2022-12-22
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
luckyshot CRMx (affected versions not specified)
Description
A critical issue was found in luckyshot CRMx, affecting the
get/save/delete/comment/commentdelete function of the index.php file. This issue leads to SQL injection and can be initiated remotely.Recommendations
To fix this issue, it is recommended to apply a patch. The patch is identified by the name
8c62d274986137d6a1d06958a6f75c3553f45f8f. As a temporary workaround, consider disabling the get/save/delete/comment/commentdelete function of the index.php file until the patch is applied.Exploit
Fix
Improper Neutralization
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Luckyshot Crmx