gitee.com
https://gitee.com/koyshe/phpshe/issues/ITC0C CVE-2019-9762
CRITICALNuclei
phpshe phpshe Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Record summary
CVE-2019-9762 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
A SQL Injection was discovered in PHPSHE 1.7 in include/plugin/payment/alipay/pay.php with the parameter id. The vulnerability does not need any authentication.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Apr 21, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
phpsheBrowse phpshe / phpshe | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALPHPSHE 1.7 - SQL InjectionCVSS 9.8
A SQL Injection was discovered in PHPSHE 1.7 in include/plugin/payment/alipay/pay.php with the parameter id. The vulnerability does not need any authentication.
Impact
Attackers can execute arbitrary SQL commands, potentially leading to data theft, modification, or deletion.
Remediation
Update to the latest version of PHPSHE or apply security patches to sanitize input parameters.
WeaknessesCWE-89
AuthorsDhiyaneshDK
Template tagscvecve2019phpshesqlivkevvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:phpshe:phpshe:1.7:*:*:*:*:*:*:*
FOFA: app="PHPSHE"
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-9762