PT-2023-10220 · Unknown · Dovgalyuk Aibattle

·

CVE-2015-10041

·

Published

2023-01-13

·

Updated

2024-08-06

CVSS v2.0

5.2

Medium

VectorAV:A/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Dovgalyuk AIBattle (affected versions not specified)
Description A critical vulnerability has been found in Dovgalyuk AIBattle. The issue affects the sendComments function of the file site/procedures.php. The manipulation of the text argument leads to SQL injection.
Recommendations Apply a patch to fix this issue. The patch is identified by the name e3aa4d0900167641d41cbccf53909229f00381c9. As a temporary workaround, consider disabling the sendComments function until a patch is available. Restrict access to the site/procedures.php file to minimize the risk of exploitation. Avoid using the text argument in the affected function until the issue is resolved.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-10041

Affected Products

Dovgalyuk Aibattle