CVE-2020-13525: SQL Injection
Published Dec 3, 2020
·Updated
The sort parameter in the download page /sysworkflow/en/neoclassic/reportTables/reportTablesAjax is vulnerable to SQL injection in ProcessMaker 3.4.11. A specially crafted HTTP request can cause an SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Affected Software
1 affected component
ProcessMaker ProcessMaker=3.4.11
Event History
Dec 3, 2020
CVE Published
via MITRE·05:04 PM
Data Sourced
via MITRE·05:04 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-13525?
CVE-2020-13525 is classified as a high severity SQL injection vulnerability.
2
How do I fix CVE-2020-13525?
To fix CVE-2020-13525, upgrade ProcessMaker to a version later than 3.4.11 that addresses this vulnerability.
3
What kind of attack can be executed through CVE-2020-13525?
CVE-2020-13525 allows an attacker to conduct SQL injection attacks through specially crafted HTTP requests.
4
Which version of ProcessMaker is affected by CVE-2020-13525?
CVE-2020-13525 affects ProcessMaker version 3.4.11.
5
Is authentication required to exploit CVE-2020-13525?
Yes, an authenticated user can exploit CVE-2020-13525 by making the vulnerable HTTP request.