Description
CrashFix 1.0.4 has SQL Injection via the User[status] parameter. This is related to actionIndex in UserController.php, and the protected\models\User.php search() function.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-13062 | CrashFix 1.0.4 has SQL Injection via the User[status] parameter. This is related to actionIndex in UserController.php, and the protected\models\User.php search() function. |
References
| Link | Providers |
|---|---|
| https://sourceforge.net/p/crashfix/tickets/21/ |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-16T19:35:14.167Z
Reserved: 2018-12-27T00:00:00.000Z
Link: CVE-2018-20508
No data.
Status : Modified
Published: 2018-12-27T13:29:00.287
Modified: 2024-11-21T04:01:38.083
Link: CVE-2018-20508
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD