vendor:
UserSpice PHP user management
by:
Dolev Farhi
7.5
CVSS
HIGH
Blind SQL Injection
89
CWE
Product Name: UserSpice PHP user management
Affected Version From: UserSpice <= 4.3
Affected Version To: UserSpice <= 4.3
Patch Exists: YES
Related CWE: N/A
CPE: a:userspice:userspice
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: N/A
2018
UserSpice <= 4.3 Blind SQL Injection exploit
Unsanitized input passed to removePermission parameter.
Mitigation:
Input validation and sanitization should be done to prevent SQL injection attacks.