Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

To contain a SQL injection #52

Open
aashiqahamedn opened this issue Mar 14, 2024 · 0 comments
Open

To contain a SQL injection #52

aashiqahamedn opened this issue Mar 14, 2024 · 0 comments

Comments

@aashiqahamedn
Copy link

aashiqahamedn commented Mar 14, 2024

Name of the Affected Product:
Reportico

Affected Version:
Till 8.1.0

Description:
This vulnerability occurs when a low privilege user is able to get internal system path, file path and DB related information by manipulating the parameter from project=admin to project=admin' in the URL. This error message allows the low privilege user to gain insights into the inner workings of the application or system, potentially leading to unintended exposure of sensitive data or exploitation of system weaknesses.

Impact:
This vulnerability can have several detrimental consequences. Firstly, the exposure of internal paths provides attackers with insights into the directory structure of the application, facilitating further exploitation. Secondly, disclosing error messages can aid attackers in refining their attack strategies and identifying potential weaknesses within the application.

image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant