The document describes SQL injection vulnerabilities in LabStoRe <= 1.5.4, providing proof-of-concept URLs with injection points in the 'where_clause' parameter. It includes a disclosure timeline and technical details about the affected endpoints.
Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target:LabStoRe <= 1.5.4
Auth required
Prerequisites:Valid account credentials · Access to vulnerable endpoints