A vulnerability classified as critical has been found in Demokratian. This affects an unknown part of the file install/install3.php. The manipulation leads to privilege escalation. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.
References
Link | Resource |
---|---|
https://alquimistadesistemas.com/sql-injection-y-archivo-peligroso-en-demokratian | Exploit Patch Third Party Advisory |
https://bitbucket.org/csalgadow/demokratian_votaciones/commits/0d073ee461edd5f42528d41e00bf0a7b22e86bb3 | Patch Third Party Advisory |
https://vuldb.com/?id.159435 | Third Party Advisory |
https://alquimistadesistemas.com/sql-injection-y-archivo-peligroso-en-demokratian | Exploit Patch Third Party Advisory |
https://bitbucket.org/csalgadow/demokratian_votaciones/commits/0d073ee461edd5f42528d41e00bf0a7b22e86bb3 | Patch Third Party Advisory |
https://vuldb.com/?id.159435 | Third Party Advisory |
Configurations
History
21 Nov 2024, 05:29
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 7.5
v3 : 7.3 |
References | () https://alquimistadesistemas.com/sql-injection-y-archivo-peligroso-en-demokratian - Exploit, Patch, Third Party Advisory | |
References | () https://bitbucket.org/csalgadow/demokratian_votaciones/commits/0d073ee461edd5f42528d41e00bf0a7b22e86bb3 - Patch, Third Party Advisory | |
References | () https://vuldb.com/?id.159435 - Third Party Advisory |
11 Jun 2022, 03:54
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://vuldb.com/?id.159435 - Third Party Advisory | |
References | (MISC) https://bitbucket.org/csalgadow/demokratian_votaciones/commits/0d073ee461edd5f42528d41e00bf0a7b22e86bb3 - Patch, Third Party Advisory | |
References | (MISC) https://alquimistadesistemas.com/sql-injection-y-archivo-peligroso-en-demokratian - Exploit, Patch, Third Party Advisory | |
CVSS |
v2 : v3 : |
v2 : 7.5
v3 : 9.8 |
CPE | cpe:2.3:a:demokratian:demokratian:-:*:*:*:*:*:*:* | |
CWE | CWE-269 |
07 Jun 2022, 18:38
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-06-07 18:15
Updated : 2024-11-21 05:29
NVD link : CVE-2020-36542
Mitre link : CVE-2020-36542
CVE.ORG link : CVE-2020-36542
JSON object : View
Products Affected
demokratian
- demokratian
CWE
CWE-269
Improper Privilege Management