First published: Tue Aug 17 2021(Updated: )
An exploitable SQL injection vulnerability exists in the ‘entities/fields’ page of the Rukovoditel Project Management App 2.7.2. The entities_id parameter in the 'entities/fields page (mulitple_edit or copy_selected or export function) is vulnerable to authenticated SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability, this can be done either with administrator credentials or through cross-site request forgery.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Rukovoditel Rukovoditel | =2.7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13589 is an SQL injection vulnerability found in the 'entities/fields' page of the Rukovoditel Project Management App version 2.7.2.
CVE-2020-13589 has a severity score of 8.8 (high).
CVE-2020-13589 affects Rukovoditel Project Management App version 2.7.2.
The CWE for CVE-2020-13589 is CWE-89 (SQL Injection).
Yes, authenticated access is required to exploit CVE-2020-13589.