SQL injection vulnerability have been found in 101news affecting version 1.0 through the "pagetitle" and "pagedescription" parameters in admin/contactus.php.
The vulnerability occurs in the 'pagetitle' and 'pagedescription' parameters handled by the admin/contactus.php script. User-supplied data is not properly validated or sanitized before being used in SQL queries (CWE-89). An attacker can inject malicious SQL code fragments over the network without needing special privileges or victim interaction, thereby gaining unauthorized access to the database.
An attacker can gain full access to the application's database, steal, modify, or delete stored data. Depending on server configuration, it is also possible to take control of the database system.
Apply patches available from the manufacturer according to the references. Additionally, it is recommended to implement parameterized SQL queries or ORM mechanisms to eliminate the SQL injection vulnerability class, as well as restrict access to the admin panel exclusively to trusted IP addresses.
101news application (Mayurik Best Online News Portal) version 1.0 — admin/contactus.php file (parameters 'pagetitle' and 'pagedescription').
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XMayurik Best Online News Portal
APPMayurik1.0
Related vulnerabilities
SQL Injection w 101news – parametry category i subcategory
SQL Injection w 101news — parametr sadminusername w panelu admina
SQL Injection w 101news (Mayurik Best Online News Portal) via parametr pagedescription
SQL Injection w 101news — podatność w parametrze 'username'
SQL Injection w 101news – parametr 'description' w panelu admina