WeBid version up to current version 1.2.2 contains a SQL Injection vulnerability in All five yourauctions*.php scripts that can result in Database Read via Blind SQL Injection. This attack appear to be exploitable via HTTP Request. This vulnerability appears to have been fixed in after commit 256a5f9d3eafbc477dcf77c7682446cc4b449c7f.
oryginał ENCVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HWebidsupport Webid
APPWebidsupport≤ 1.2.2
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
SQLi
CWE
Referencje
Powiązane podatności
CVE-2024-35409CRITICAL9.8PL ✓ten sam produkt
SQL Injection w WeBid 1.1.2 via admin/tax.php
CVE-2023-47397CRITICAL9.8PL ✓ten sam produkt
WeBid ≤1.2.2 — code injection w panelu administracyjnym
CVE-2022-41477CRITICAL9.1PL ✓ten sam produkt
SSRF w WeBid — odczyt plików przez parametry motywu (theme)
CVE-2020-23359CRITICAL9.8PL ✓ten sam produkt
WeBid: błędna weryfikacja haseł podczas rejestracji (loose comparison)
CVE-2024-32166HIGH8.8ten sam produkt
Webid v1.2.1 suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, al...