CVE-2018-20716: SQL Injection
Published Jan 15, 2019
·Updated
CubeCart before 6.1.13 has SQL Injection via the validate[] parameter of the "I forgot my Password!" feature.
Affected Software
1 affected component
Cubecart CubeCart<6.1.13
Event History
Jan 15, 2019
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-20716?
CVE-2018-20716 refers to a SQL Injection vulnerability in CubeCart versions before 6.1.13.
2
How severe is CVE-2018-20716?
CVE-2018-20716 has a severity score of 9.8 (critical).
3
How can I fix CVE-2018-20716?
To fix CVE-2018-20716, you should update CubeCart to version 6.1.13 or later.
4
What is the affected software for CVE-2018-20716?
The affected software for CVE-2018-20716 is CubeCart versions before 6.1.13.
5
What is the CWE ID for CVE-2018-20716?
The CWE ID for CVE-2018-20716 is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command).