#VU29923 SQL injection in SRS Simple Hits Counter - CVE-2020-5766

 

#VU29923 SQL injection in SRS Simple Hits Counter - CVE-2020-5766

Published: July 15, 2020 / Updated: July 15, 2020


Vulnerability identifier: #VU29923
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/U:Green
CVE-ID: CVE-2020-5766
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
SRS Simple Hits Counter
Software vendor:
Atif N

Description

The vulnerability allows a remote attacker to execute arbitrary SQL queries in database.

The vulnerability exists due to insufficient sanitization of user-supplied data in the "srs_simple_hits_counter" function. A remote attacker can send a specially crafted request to the affected application and gain sensitive information on the target system.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability..

External links