vendor:
Textpattern
by:
Manuel García Cárdenas
9.8
CVSS
CRITICAL
SQL Injection in Textpattern <= 4.6.2
89
CWE
Product Name: Textpattern
Affected Version From: Textpattern <= 4.6.2
Affected Version To: Textpattern <= 4.6.2
Patch Exists: NO
Related CWE: CVE-2018-7474
CPE: a:textpattern:textpattern:4.6.2
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
MGC ALERT 2018-002
This bug was found using the portal with authentication as administrator. To exploit the vulnerability only is needed use the version 1.0 of the HTTP protocol to interact with the application. It is possible to inject SQL code in the variable 'qty' on the page 'index.php'.
Mitigation:
Disable website until a fix is available.