vendor:
HM-Community
by:
599eme Man
8.8
CVSS
HIGH
SQL, Blind SQL, Persistent XSS
89, 89, 79
CWE
Product Name: HM-Community
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020
Joomla Compenent com_hmcommunity Multiple Vulnerabilities
The SQL vulnerability is an injection vulnerability that can be exploited by sending a maliciously crafted HTTP request to the vulnerable application. The Blind SQL vulnerability is an injection vulnerability that can be exploited by sending a maliciously crafted HTTP request to the vulnerable application. The Persistent XSS vulnerability is an injection vulnerability that can be exploited by creating an account and putting malicious code in the inputs. The demo for this vulnerability is to create an account and look at the profile of the user with the ID 155.
Mitigation:
Input validation, Input validation, Input validation