Exploitation Summary
EIP tracks 1 public exploit for CVE-2018-25202. PoCs published by AkkuS.
AI-analyzed exploit summary The exploit demonstrates SQL injection in SAT CFDI 3.3 via the 'id' parameter in the signIn endpoint. It includes multiple payloads for boolean-based blind, time-based blind, and stacked query attacks.
Description
SAT CFDI 3.3 contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the 'id' parameter in the signIn endpoint. Attackers can submit POST requests with boolean-based blind, stacked queries, or time-based blind SQL injection payloads to extract sensitive data or compromise the application.
Exploits (1)
The exploit demonstrates SQL injection in SAT CFDI 3.3 via the 'id' parameter in the signIn endpoint. It includes multiple payloads for boolean-based blind, time-based blind, and stacked query attacks.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N