PT-2022-27686 · Unknown · Luckyshot Crmx

CVE-2022-4592

·

Published

2022-12-18

·

Updated

2022-12-22

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions luckyshot CRMx (affected versions not specified)
Description A critical issue was found in luckyshot CRMx, affecting the get/save/delete/comment/commentdelete function of the index.php file. This issue leads to SQL injection and can be initiated remotely.
Recommendations To fix this issue, it is recommended to apply a patch. The patch is identified by the name 8c62d274986137d6a1d06958a6f75c3553f45f8f. As a temporary workaround, consider disabling the get/save/delete/comment/commentdelete function of the index.php file until the patch is applied.

Exploit

Fix

Improper Neutralization

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-4592

Affected Products

Luckyshot Crmx