UNKNOWNCVE-2018-25195
Wecodex Hotel CMS 1.0 SQL Injection via Admin Login
Platform
php
Component
wecodex-hotel-cms
Wecodex Hotel CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows unauthenticated attackers to bypass authentication by injecting SQL code. Attackers can submit malicious SQL payloads through the username parameter in POST requests to index.php with action=processlogin to extract sensitive database information or gain unauthorized administrative access.
How to fix
Actualizar a una versión parcheada o aplicar las medidas de seguridad recomendadas por el proveedor para mitigar la vulnerabilidad de inyección SQL. Se recomienda contactar al proveedor para obtener un parche específico o instrucciones detalladas.
Monitor your dependencies automatically
Get notified when new vulnerabilities affect your projects. Free forever.
Start free