CVE-2015-10070

MEDIUM

twiddit < 2015-03-18 - SQL Injection in index.php

Title source: llm
STIX 2.1

Description

A vulnerability was found in copperwall Twiddit. It has been rated as critical. This issue affects some unknown processing of the file index.php. The manipulation leads to sql injection. The identifier of the patch is 2203d4ce9810bdaccece5c48ff4888658a01acfc. It is recommended to apply a patch to fix this issue. The identifier VDB-218897 was assigned to this vulnerability.

References (3)

Core 3
Core References
Permissions Required, Third Party Advisory vdb-entry technical-description
https://vuldb.com/?id.218897
Permissions Required, Third Party Advisory signature permissions-required
https://vuldb.com/?ctiid.218897

Scores

CVSS v3 6.3
EPSS 0.0073
EPSS Percentile 50.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-89
Status published
Products (1)
twiddit_project/twiddit < 2015-03-18
Published Jan 19, 2023
Tracked Since Feb 18, 2026