vendor:
OpenExpert
by:
Nassim Asrir
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: OpenExpert
Affected Version From: 0.5.17
Affected Version To: 0.5.17
Patch Exists: YES
Related CWE: N/A
CPE: a:openexpert:openexpert:0.5.17
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Winxp sp3 - win7
2018
Openexpert 0.5.17 – Sql Injection
OpenExpert is vulnerable to SQL Injection via the 'area_id' parameter. An attacker can exploit this vulnerability by sending a malicious HTTP GET request to the vulnerable server. The SQL query used returns 5 entries, including information_schema, mysql, performance_schema, sys, and test.
Mitigation:
Upgrade to the latest version of OpenExpert and sanitize user input.