CVE-2015-10019

A vulnerability, which was classified as problematic, has been found in foxoverflow MySimplifiedSQL. This issue affects some unknown processing of the file MySimplifiedSQL_Examples.php. The manipulation of the argument FirstName/LastName leads to cross site scripting. The attack may be initiated remotely. The patch is named 3b7481c72786f88041b7c2d83bb4f219f77f1293. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217595.
References
Link Resource
https://github.com/foxoverflow/MySimplifiedSQL/commit/3b7481c72786f88041b7c2d83bb4f219f77f1293 Patch Third Party Advisory
https://vuldb.com/?ctiid.217595 Third Party Advisory VDB Entry
https://vuldb.com/?id.217595 Permissions Required Third Party Advisory VDB Entry
https://github.com/foxoverflow/MySimplifiedSQL/commit/3b7481c72786f88041b7c2d83bb4f219f77f1293 Patch Third Party Advisory
https://vuldb.com/?ctiid.217595 Third Party Advisory VDB Entry
https://vuldb.com/?id.217595 Permissions Required Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:mysimplifiedsql_project:mysimplifiedsql:*:*:*:*:*:*:*:*

History

21 Nov 2024, 02:24

Type Values Removed Values Added
References () https://github.com/foxoverflow/MySimplifiedSQL/commit/3b7481c72786f88041b7c2d83bb4f219f77f1293 - Patch, Third Party Advisory () https://github.com/foxoverflow/MySimplifiedSQL/commit/3b7481c72786f88041b7c2d83bb4f219f77f1293 - Patch, Third Party Advisory
References () https://vuldb.com/?ctiid.217595 - Third Party Advisory, VDB Entry () https://vuldb.com/?ctiid.217595 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?id.217595 - Permissions Required, Third Party Advisory, VDB Entry () https://vuldb.com/?id.217595 - Permissions Required, Third Party Advisory, VDB Entry
CVSS v2 : 4.0
v3 : 6.1
v2 : 4.0
v3 : 3.5

29 Feb 2024, 01:16

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad fue encontrada en foxoverflow MySimplifiedSQL y clasificada como problemática. Este problema afecta un procesamiento desconocido del archivo MySimplifiedSQL_Examples.php. La manipulación del argumento Nombre/Apellido conduce a cross site scripting. El ataque puede iniciarse de forma remota. El parche se llama 3b7481c72786f88041b7c2d83bb4f219f77f1293. Se recomienda aplicar un parche para solucionar este problema. El identificador asociado de esta vulnerabilidad es VDB-217595.

Information

Published : 2023-01-07 09:15

Updated : 2024-11-21 02:24


NVD link : CVE-2015-10019

Mitre link : CVE-2015-10019

CVE.ORG link : CVE-2015-10019


JSON object : View

Products Affected

mysimplifiedsql_project

  • mysimplifiedsql
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')