vendor:
Maitra - Mail Tracking System
by:
Ihsan Sencan
7.5
CVSS
HIGH
SQL Injection / Database File Download
CWE
Product Name: Maitra - Mail Tracking System
Affected Version From: 1.7.2002
Affected Version To: 1.7.2002
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: WiN7_x64/KaLiLinuX_x64
2018
Maitra – Mail Tracking System 1.7.2 – SQL Injection / Database File Download
The Maitra - Mail Tracking System 1.7.2 is vulnerable to SQL Injection and allows an attacker to download the database file. The vulnerability can be exploited by accessing the /application/db/maitra.sqlite file or by using the /?c=outmail&m=outmailentry&mailid=[SQL] endpoint with a malicious SQL query.
Mitigation:
The vendor has not provided a patch for this vulnerability. To mitigate the risk, it is recommended to restrict access to the vulnerable files and endpoints, and to regularly monitor and update the software.