CVE-2019-11451: SQL Injection
Published Apr 22, 2019
·Updated
whatsns 4.0 allows index.php?inform/add.html qid SQL injection.
Affected Software
1 affected component
Whatsns Whatsns=4.0
Event History
Apr 22, 2019
CVE Published
via MITRE·02:12 PM
Data Sourced
via MITRE·02:12 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-11451?
CVE-2019-11451 has a severity score that indicates it can lead to SQL injection vulnerabilities in Whatsns version 4.0.
2
How do I fix CVE-2019-11451?
To mitigate CVE-2019-11451, you should apply security updates provided by Whatsns or sanitize user inputs to prevent SQL injection.
3
What components are affected by CVE-2019-11451?
CVE-2019-11451 specifically affects Whatsns version 4.0.
4
What is the exploit path for CVE-2019-11451?
CVE-2019-11451 can be exploited through the index.php?inform/add.html endpoint by injecting malicious SQL queries using the 'qid' parameter.
5
Are earlier versions of Whatsns affected by CVE-2019-11451?
CVE-2019-11451 is reported to affect only Whatsns version 4.0 and does not mention earlier versions.