CVE-2018-15918: SQL Injection
An issue was discovered in Jorani 0.6.5. SQL Injection (error-based) allows a user of the application without permissions to read and modify sensitive information from the database used by the application via the startdate or enddate parameter to leaves/validate.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-15918?
CVE-2018-15918 is a vulnerability in Jorani 0.6.5 that allows an unauthorized user to perform SQL injection attacks and access sensitive information from the application's database.
How does CVE-2018-15918 impact Jorani?
CVE-2018-15918 allows an attacker without proper permissions to read and modify sensitive information in Jorani's database using the startdate or enddate parameter in the leaves/validate functionality.
What is the severity of CVE-2018-15918?
The severity of CVE-2018-15918 is rated as medium with a CVSS score of 5.4.
How can I fix CVE-2018-15918 in Jorani?
To fix CVE-2018-15918, you should update Jorani to a version that is not affected by the vulnerability, such as a version higher than 0.6.5.
Are there any references related to CVE-2018-15918?
Yes, you can find more information about CVE-2018-15918 in the following references: [link1] [link2] [link3].