Deepwoods Software WebLibrarian 3.5.2 and earlier is affected by: SQL Injection
Published Jul 15, 2019
6.5
MEDIUMCVSS 3.0
EPSS 1.43%
Description
Deepwoods Software WebLibrarian 3.5.2 and earlier is affected by: SQL Injection. The impact is: Exposing the entire database. The component is: Function "AllBarCodes" (defined at database_code.php line 1018) is vulnerable to a boolean-based blind sql injection. This function call can be triggered by any user logged-in with at least Volunteer role or manage_circulation capabilities. PoC : /wordpress/wp-admin/admin.php?page=weblib-circulation-desk&orderby=title&order=DESC.
Affected products
-
- Version ≤ 3.5.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Deepwoods Software | WebLibrarian | n/a |
|
- ≤ 3.5.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- https://plugins.trac.wordpress.org/browser/weblibrarian/trunk/includes/database_code.php x_refsource_MISCExploitThird Party Advisory
- https://wpvulndb.com/vulnerabilities/9553 x_refsource_MISC
| Link | Providers | Tags |
|---|---|---|
| https://plugins.trac.wordpress.org/browser/weblibrarian/trunk/includes/database_code.php | x_refsource_MISCExploitThird Party Advisory | |
| https://wpvulndb.com/vulnerabilities/9553 | x_refsource_MISC |
Change history (0)
No recorded changes yet.