• caglararli@hotmail.com
  • 05386281520

CVE-2024-0527 | CXBSoft Url-shorting up to 1.3.1 HTTP POST Request update_go.php version sql injection

Çağlar Arlı      -    18 Views

CVE-2024-0527 | CXBSoft Url-shorting up to 1.3.1 HTTP POST Request update_go.php version sql injection

A vulnerability, which was classified as critical, has been found in CXBSoft Url-shorting up to 1.3.1. This issue affects some unknown processing of the file /admin/pages/update_go.php of the component HTTP POST Request Handler. The manipulation of the argument version leads to sql injection. The identification of this vulnerability is CVE-2024-0527. Access to the local network is required for this attack to succeed. Furthermore, there is an exploit available. The vendor was contacted early about this disclosure but did not respond in any way.