github.com
https://github.com/FrontAccountingERP/FA/issues/37 CVE-2018-1000890
HIGH
FrontAccounting 2.4.5 - 'SubmitUser' SQL Injection
Record summary
CVE-2018-1000890 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.
Description
FrontAccounting 2.4.5 contains a Time Based Blind SQL Injection vulnerability in the parameter "filterType" in /attachments.php that can allow the attacker to grab the entire database of the application.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBFrontAccounting 2.4.5 - 'SubmitUser' SQL InjectionExploitDB exploitby Sainadh JamalpurNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-1000890 46037exploit
https://www.exploit-db.com/exploits/46037