CVE-2020-25990: SQL Injection
WebsiteBaker 2.12.2 allows SQL Injection via parameter 'displayname' in /websitebaker/admin/preferences/save.php. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-25990?
CVE-2020-25990 has a high severity rating due to its potential for SQL injection attacks.
How do I fix CVE-2020-25990?
To fix CVE-2020-25990, upgrade to the latest version of WebsiteBaker or implement input sanitization on the 'display_name' parameter.
What are the potential impacts of CVE-2020-25990?
Exploiting CVE-2020-25990 could allow attackers to compromise the application, access sensitive data, or manipulate the database.
Who is affected by CVE-2020-25990?
Websites running WebsiteBaker version 2.12.2 are affected by CVE-2020-25990.
Can CVE-2020-25990 lead to complete server compromise?
Yes, CVE-2020-25990 can potentially lead to full server compromise through SQL injection, allowing attackers to gain elevated privileges.