What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone allows SQL Injection.This issue affects WZone: from n/a through 14.0.10.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
What the vulnerability does
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone allows SQL Injection.This issue affects WZone: from n/a through 14.0.10.
Explanation of Vulnerability in Simple Terms
WZone versions up to 14.0.10 contain a SQL injection vulnerability that allows authenticated users to execute arbitrary SQL queries. An attacker with low-level access can modify or delete database records, and the scope of impact extends beyond the vulnerable component. No user interaction is required to exploit this flaw.
What an attacker can do
Execute arbitrary SQL commands to read, modify, or delete database records.
Potential impact on your site
Attackers with user accounts can corrupt or exfiltrate your database, affecting data integrity and availability.
Conditions required to exploit
Attacker must have a valid user account with low-level privileges on the WZone installation.
Key dates
External resources
Related vulnerabilities