What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in miniorange Malware Scanner.This issue affects Malware Scanner: from n/a through 4.7.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in miniorange Malware Scanner.This issue affects Malware Scanner: from n/a through 4.7.2.
Explanation of Vulnerability in Simple Terms
A SQL injection vulnerability in miniOrange Malware Scanner versions up to 4.7.2 allows authenticated administrators to execute arbitrary SQL queries. An attacker with high-level admin privileges can read or modify database contents. The vulnerability requires network access and admin credentials but does not require user interaction.
What an attacker can do
Execute arbitrary SQL queries to read or modify the site's database.
Potential impact on your site
An admin account compromise could expose sensitive data or corrupt your database.
Conditions required to exploit
Attacker must have administrator-level access to the site.
Key dates
External resources
Related vulnerabilities