CVE-2019-25713
HIGHMyT-PM 1.5.1 SQL Injection via Charge[group_total] Parameter
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25713. PoCs published by Mehmet Onder.
AI-analyzed exploit summary The exploit demonstrates SQL injection in MyT-PM 1.5.1 via the 'Charge[group_total]' POST parameter. It includes error-based, time-based blind, and stacked query payloads targeting the '/charge/admin' endpoint.
Description
MyT-PM 1.5.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the Charge[group_total] parameter. Attackers can submit crafted POST requests to the /charge/admin endpoint with error-based, time-based blind, or stacked query payloads to extract sensitive database information or manipulate data.
Exploits (1)
The exploit demonstrates SQL injection in MyT-PM 1.5.1 via the 'Charge[group_total]' POST parameter. It includes error-based, time-based blind, and stacked query payloads targeting the '/charge/admin' endpoint.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N