What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2.
Explanation of Vulnerability in Simple Terms
MoveTo versions 6.2 and earlier contain a SQL injection vulnerability in an unspecified component. An attacker can send a specially crafted network request to execute arbitrary SQL commands on the database without authentication. This allows complete compromise of the database, including reading, modifying, or deleting data. No user interaction is required.
What an attacker can do
Execute arbitrary SQL commands to read, modify, or delete database contents without authentication.
Potential impact on your site
Complete database compromise: attackers can steal user data, modify site content, or destroy the database.
Conditions required to exploit
Network access to the MoveTo application. No authentication or user interaction required.
Key dates
External resources
Related vulnerabilities