First published: Thu Jul 25 2019(Updated: )
OpenSNS v6.1.0 allows SQL Injection via the index.php?s=/ucenter/Config/ uid parameter because of the getNeedQueryData function in Application/Common/Model/UserModel.class.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opensns Opensns | =6.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14266 is a vulnerability in OpenSNS v6.1.0 that allows SQL Injection via the uid parameter.
CVE-2019-14266 has a severity rating of 8.8 (high).
CVE-2019-14266 allows an attacker to perform SQL Injection attacks through the uid parameter in OpenSNS v6.1.0.
To fix CVE-2019-14266 in OpenSNS v6.1.0, you need to update to a version that addresses the SQL Injection vulnerability.
More information about CVE-2019-14266 can be found at https://github.com/kikulo/DebugOpen/blob/master/OpenSNSv6.1.0/main.md.