Gimmie Plugin trigger_login.php sql injection
Published Feb 6, 2023
9.8
CRITICALCVSS 3.1
EPSS 0.67%
Description
A vulnerability has been found in Gimmie Plugin 1.2.2 on vBulletin and classified as critical. Affected by this vulnerability is an unknown functionality of the file trigger_login.php. The manipulation of the argument userid leads to sql injection. Upgrading to version 1.3.0 is able to address this issue. The patch is named fe851002d20a8d6196a5abb68bafec4102964d5b. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-220207.
Affected products
- Vendor n/a Product Gimmie Plugin Defaultunknown
Affected
- 1.2.2
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Gimmie Plugin | unknown | Affected
|
- < 1.3.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2014-1255 Advisory
- https://github.com/gimmie/vbulletin-v4/commit/fe851002d20a8d6196a5abb68bafec4102964d5b patchThird Party Advisory
- https://github.com/gimmie/vbulletin-v4/tree/v1.3.0 patchRelease NotesThird Party Advisory
- https://vuldb.com/?ctiid.220207 signaturepermissions-requiredPermissions RequiredThird Party Advisory
- https://vuldb.com/?id.220207 vdb-entrytechnical-descriptionPermissions RequiredThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2014-1255 | Advisory | |
| https://github.com/gimmie/vbulletin-v4/commit/fe851002d20a8d6196a5abb68bafec4102964d5b | patchThird Party Advisory | |
| https://github.com/gimmie/vbulletin-v4/tree/v1.3.0 | patchRelease NotesThird Party Advisory | |
| https://vuldb.com/?ctiid.220207 | signaturepermissions-requiredPermissions RequiredThird Party Advisory | |
| https://vuldb.com/?id.220207 | vdb-entrytechnical-descriptionPermissions RequiredThird Party Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data