CVE-2020-11004
24.04.2020, 21:15
SQL Injection was discovered in Admidio before version 3.3.13. The main cookie parameter is concatenated into a SQL query without any input validation/sanitization, thus an attacker without logging in, can send a GET request with arbitrary SQL queries appended to the cookie parameter and execute SQL queries. The vulnerability impacts the confidentiality of the system. This has been patched in version 3.3.13.
| Vendor | Product | Version |
|---|---|---|
| admidio | admidio | 𝑥 < 3.3.13 |
𝑥
= Vulnerable software versions
References