CVE-2017-20168

A vulnerability was found in jfm-so piWallet. It has been rated as critical. Affected by this issue is some unknown functionality of the file api.php. The manipulation of the argument key leads to sql injection. The patch is identified as b420f8c4cbe7f06a34d1b05e90ee5cdfe0aa83bb. It is recommended to apply a patch to fix this issue. VDB-218006 is the identifier assigned to this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:piwallet_project:piwallet:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:22

Type Values Removed Values Added
CVSS v2 : 5.2
v3 : 9.8
v2 : 5.2
v3 : 5.5
References () https://github.com/jfm-so/piWallet/commit/b420f8c4cbe7f06a34d1b05e90ee5cdfe0aa83bb - Patch () https://github.com/jfm-so/piWallet/commit/b420f8c4cbe7f06a34d1b05e90ee5cdfe0aa83bb - Patch
References () https://github.com/jfm-so/piWallet/pull/23 - Patch () https://github.com/jfm-so/piWallet/pull/23 - Patch
References () https://vuldb.com/?ctiid.218006 - Permissions Required, Third Party Advisory () https://vuldb.com/?ctiid.218006 - Permissions Required, Third Party Advisory
References () https://vuldb.com/?id.218006 - Permissions Required, Third Party Advisory () https://vuldb.com/?id.218006 - Permissions Required, Third Party Advisory
Summary
  • (es) Se encontró una vulnerabilidad en jfm-so piWallet. Ha sido calificada como crítica. Una función desconocida del archivo api.php es afectada por esta vulnerabilidad. La manipulación de la clave del argumento conduce a la inyección SQL. El parche se identifica como b420f8c4cbe7f06a34d1b05e90ee5cdfe0aa83bb. Se recomienda aplicar un parche para solucionar este problema. VDB-218006 es el identificador asignado a esta vulnerabilidad.

29 Feb 2024, 01:20

Type Values Removed Values Added
New CVE

Information

Published : 2023-01-11 15:15

Updated : 2024-11-21 03:22


NVD link : CVE-2017-20168

Mitre link : CVE-2017-20168

CVE.ORG link : CVE-2017-20168


JSON object : View

Products Affected

piwallet_project

  • piwallet
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')