First published: Thu Apr 16 2020(Updated: )
Rukovoditel 2.5.2 is affected by a SQL injection vulnerability because of improper handling of the filters[0][value] or filters[1][value] parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Rukovoditel Rukovoditel | =2.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-11812 is a SQL injection vulnerability in Rukovoditel 2.5.2.
CVE-2020-11812 affects Rukovoditel 2.5.2 by allowing an attacker to perform SQL injection through the filters[0][value] or filters[1][value] parameter.
CVE-2020-11812 has a severity rating of critical with a score of 9.8.
To fix CVE-2020-11812, it is recommended to update Rukovoditel to a version that has addressed the SQL injection vulnerability.
You can find more information about CVE-2020-11812 in the following references: - [Blog post 1](https://fatihhcelik.blogspot.com/2020/01/rukovoditel-sql-injection-filters0value.html) - [Blog post 2](https://fatihhcelik.blogspot.com/2020/01/rukovoditel-sql-injection-filters1value.html)