HIGH🇵🇱 Wersja polska

CVE-2018-1000867

CVSS 8.8v3.0pub. 2018-12-20upd. 2024-11-21

WeBid version up to current version 1.2.2 contains a SQL Injection vulnerability in All five yourauctions*.php scripts that can result in Database Read via Blind SQL Injection. This attack appear to be exploitable via HTTP Request. This vulnerability appears to have been fixed in after commit 256a5f9d3eafbc477dcf77c7682446cc4b449c7f.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Webidsupport Webid

    APP
    Webidsupport
    ≤ 1.2.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2024-35409CRITICAL9.8PL ✓same product

SQL Injection w WeBid 1.1.2 via admin/tax.php

CVE-2023-47397CRITICAL9.8PL ✓same product

WeBid ≤1.2.2 — code injection w panelu administracyjnym

CVE-2022-41477CRITICAL9.1PL ✓same product

SSRF w WeBid — odczyt plików przez parametry motywu (theme)

CVE-2020-23359CRITICAL9.8PL ✓same product

WeBid: błędna weryfikacja haseł podczas rejestracji (loose comparison)

CVE-2024-32166HIGH8.8same product

Webid v1.2.1 suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, al...