vendor:
ResourceSpace
by:
dd_ (info@malicious.group)
7.5
CVSS
HIGH
SQL Injection
CWE
Product Name: ResourceSpace
Affected Version From: Stable release: 8.6
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: PHP/MySQL (PHP 7.2 / MySQL 5.7.25-0ubuntu0.18.04.2-log)
2019
ResourceSpace <=8.6 'collection_edit.php' SQL Injection
The 'collection_edit.php' page in ResourceSpace version 8.6 is vulnerable to SQL Injection. An attacker can exploit this vulnerability by injecting malicious SQL code through the 'keywords' parameter.
Mitigation:
Upgrade to a version higher than 8.6 or apply the vendor's patch.