What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in KaizenCoders Short URL allows SQL Injection.This issue affects Short URL: from n/a through 1.6.4.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in KaizenCoders Short URL allows SQL Injection.This issue affects Short URL: from n/a through 1.6.4.
Explanation of Vulnerability in Simple Terms
Short URL versions up to 1.6.4 contain a SQL injection vulnerability in database query handling. An authenticated user with low privileges can inject malicious SQL commands through input fields, potentially reading sensitive data from the database or disrupting site availability. The vulnerability affects multiple database operations and requires only network access and valid login credentials.
What an attacker can do
Read sensitive data from the database or cause the site to become unavailable.
Potential impact on your site
Unauthorized database access, data exposure, or denial of service affecting site stability and user data confidentiality.
Conditions required to exploit
Attacker must have a valid user account with low-level privileges and network access to the site.
Key dates
External resources
Related vulnerabilities