First published: Mon Apr 22 2019(Updated: )
whatsns 4.0 allows index.php?inform/add.html qid SQL injection.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
=4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11451 has a severity score that indicates it can lead to SQL injection vulnerabilities in Whatsns version 4.0.
To mitigate CVE-2019-11451, you should apply security updates provided by Whatsns or sanitize user inputs to prevent SQL injection.
CVE-2019-11451 specifically affects Whatsns version 4.0.
CVE-2019-11451 can be exploited through the index.php?inform/add.html endpoint by injecting malicious SQL queries using the 'qid' parameter.
CVE-2019-11451 is reported to affect only Whatsns version 4.0 and does not mention earlier versions.