SQL injection vulnerability have been found in 101news affecting version 1.0 through the "description" parameter in admin/add-category.php.
The attacker sends specially crafted input data through the 'description' parameter in the category addition form (admin/add-category.php). The application does not filter or parametrize the passed values, allowing arbitrary SQL commands to be injected directly into the query executed on the database server. The attack can be performed remotely, without authentication, and without any interaction on the victim's side.
An attacker can gain unauthorized access to data stored in the database, including authentication credentials, website content, and user data. Depending on server configuration, it is also possible to modify or delete data, and potentially execute system commands.
Patches available from the manufacturer should be applied according to references. It is also recommended to implement parameterized SQL queries (prepared statements) and validation and sanitization of input data on the server side. Until the patch is applied, consider restricting access to the admin panel only to trusted IP addresses.
101news application (Mayurik Best Online News Portal) version 1.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XMayurik Best Online News Portal
APPMayurik1.0
Related vulnerabilities
SQL Injection w 101news – parametry category i subcategory
SQL Injection w 101news — parametr sadminusername w panelu admina
SQL Injection w 101news (Mayurik Best Online News Portal) via parametr pagedescription
SQL Injection w 101news — podatność w parametrze 'username'
SQL Injection w 101news przez parametry pagetitle i pagedescription