CVE-2018-25072

A vulnerability classified as critical has been found in lojban jbovlaste. This affects an unknown part of the file dict/listing.html. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The patch is named 6ff44c2e87b1113eb07d76ea62e1f64193b04d15. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217647.
Configurations

Configuration 1 (hide)

cpe:2.3:a:lojban:jbovlaste:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:03

Type Values Removed Values Added
CVSS v2 : 6.5
v3 : 9.8
v2 : 6.5
v3 : 6.3
References () https://github.com/lojban/jbovlaste/commit/6ff44c2e87b1113eb07d76ea62e1f64193b04d15 - Patch () https://github.com/lojban/jbovlaste/commit/6ff44c2e87b1113eb07d76ea62e1f64193b04d15 - Patch
References () https://vuldb.com/?ctiid.217647 - Third Party Advisory () https://vuldb.com/?ctiid.217647 - Third Party Advisory
References () https://vuldb.com/?id.217647 - Third Party Advisory () https://vuldb.com/?id.217647 - Third Party Advisory

11 Apr 2024, 01:02

Type Values Removed Values Added
Summary
  • (es) Se ha encontrado una vulnerabilidad en lojban jbovlaste y ha sido clasificada como crítica. Esto afecta a una parte desconocida del archivo dict/listing.html. La manipulación conduce a una inyección de SQL. Es posible iniciar el ataque de forma remota. El parche se llama 6ff44c2e87b1113eb07d76ea62e1f64193b04d15. Se recomienda aplicar un parche para solucionar este problema. El identificador asociado de esta vulnerabilidad es VDB-217647.

Information

Published : 2023-01-08 13:15

Updated : 2024-11-21 04:03


NVD link : CVE-2018-25072

Mitre link : CVE-2018-25072

CVE.ORG link : CVE-2018-25072


JSON object : View

Products Affected

lojban

  • jbovlaste
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')