vendor:
eFront
by:
Filippo Roncari | Luca De Fulgentis
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: eFront
Affected Version From: 3.6.15
Affected Version To: 3.6.15
Patch Exists: NO
Related CWE: <requested>
CPE: efront
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Any unprivileged authenticated user (e.g., student or professor)
2015
eFront 3.6.15 Multiple SQL Injection Vulnerabilities
The new_sidebar.php module, which handles the left side bar in eFront 3.6.15 default theme, is affected by two SQL injection vulnerabilities due to lack of user input sanitization. The identified issues allow unprivileged users, such as professors and students (under certain conditions), to inject arbitrary SQL statements. An attacker could exploit the vulnerabilities by sending specially crafted requests to the web application. These issues can lead to data theft, data disruption, account violation and other impacts depending on the DBMS’s user privileges.
Mitigation:
Input validation and sanitization should be implemented to prevent SQL injection attacks.