CVE-2019-25359
HIGHSD.NET RIM < 4.7.3c - SQL Injection via POST Parameters 'idtyp' and 'idgremium'
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25359. PoCs published by Fabian Mosch_ Nick Theisinger.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in SD.NET RIM versions before 4.7.3c. The vulnerability is exploited by injecting arbitrary SQL statements into the 'idtyp' and 'idgremium' POST parameters, which are then executed upon a subsequent GET request.
Description
SD.NET RIM versions before 4.7.3c contain a SQL injection vulnerability that allows attackers to inject malicious SQL statements through POST parameters 'idtyp' and 'idgremium'. Attackers can exploit this vulnerability by crafting specially formed POST requests to the /vorlagen/ endpoint, enabling unauthorized database manipulation and potential information disclosure.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in SD.NET RIM versions before 4.7.3c. The vulnerability is exploited by injecting arbitrary SQL statements into the 'idtyp' and 'idgremium' POST parameters, which are then executed upon a subsequent GET request.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N