MEDIUM
An issue was discovered in Jorani 0.6.5
Published Sep 5, 2018
5.4
MEDIUMCVSS 3.0
EPSS 2.87%
Description
An issue was discovered in Jorani 0.6.5. SQL Injection (error-based) allows a user of the application without permissions to read and modify sensitive information from the database used by the application via the startdate or enddate parameter to leaves/validate.
Affected products
No data.
- 0.6.5
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-7774 Advisory
- https://github.com/bbalet/jorani/issues/254 x_refsource_MISCIssue TrackingVendor Advisory
- https://hackpuntes.com/cve-2018-15918-jorani-leave-management-system-0-6-5-sql-injection/ x_refsource_MISCExploitThird Party Advisory
- https://www.exploit-db.com/exploits/45340/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-7774 | Advisory | |
| https://github.com/bbalet/jorani/issues/254 | x_refsource_MISCIssue TrackingVendor Advisory | |
| https://hackpuntes.com/cve-2018-15918-jorani-leave-management-system-0-6-5-sql-injection/ | x_refsource_MISCExploitThird Party Advisory | |
| https://www.exploit-db.com/exploits/45340/ | exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 5, 2018
Updated Aug 5, 2024
Reserved Aug 28, 2018
Link CVE-2018-15918
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2018-7774 Assigner mitre
Published Sep 5, 2018
Updated Aug 5, 2024
Exploited since n/a
Link EUVD-2018-7774