vendor:
YouPHPTube
by:
Fabian Mosch
5.3
CVSS
MEDIUM
SQL Injection
89
CWE
Product Name: YouPHPTube
Affected Version From: < 7.3
Affected Version To: < 7.3
Patch Exists: YES
Related CWE: CVE-2019-14430
CPE: a:youphptube:youphptube
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux/Windows
2019
YouPHPTube < 7.3 SQL Injection
The parameters 'User' as well as 'pass' of the user registration function are vulnerable to SQL injection vulnerabilities. By submitting an HTTP POST request to the URL '/objects/userCreate.json.php' an attacker can access the database and read the hashed credentials of an administrator for example. Methods for DB-Extraction are: Boolean-based blind, Error-based, AND/OR time-based blind.
Mitigation:
The vulnerability was fixed with this commit: https://github.com/YouPHPTube/YouPHPTube/commit/891843d547f7db5639925a67b7f2fd66721f703a