CVE-2018-13045: SQL Injection
Published Jan 2, 2019
·Updated
SQL injection vulnerability in the "Bazar" page in Yeswiki Cercopitheque 2018-06-19-1 and earlier allows attackers to execute arbitrary SQL commands via the "id" parameter.
Affected Software
1 affected component
YesWiki Cercopitheque<=2018-06-19-1
Event History
Jan 2, 2019
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-13045?
CVE-2018-13045 has a medium severity rating due to its potential for SQL injection vulnerabilities.
2
How do I fix CVE-2018-13045?
To fix CVE-2018-13045, update Yeswiki Cercopitheque to a version later than 2018-06-19-1.
3
What types of systems are affected by CVE-2018-13045?
CVE-2018-13045 affects all versions of Yeswiki Cercopitheque up to and including 2018-06-19-1.
4
What attack vectors are possible with CVE-2018-13045?
Attackers can exploit CVE-2018-13045 to execute arbitrary SQL commands via the 'id' parameter.
5
What can attackers achieve by exploiting CVE-2018-13045?
By exploiting CVE-2018-13045, attackers can manipulate the database and potentially gain unauthorized access to sensitive information.