Security Advisory

CVE-2020-11004

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2020-04-24 20:25:14
Last updated 2024-08-04 11:21:14
Assigner GitHub_M
CVSS score 7.7
State PUBLISHED

Description

SQL Injection was discovered in Admidio before version 3.3.13. The main cookie parameter is concatenated into a SQL query without any input validation/sanitization, thus an attacker without logging in, can send a GET request with arbitrary SQL queries appended to the cookie parameter and execute SQL queries. The vulnerability impacts the confidentiality of the system. This has been patched in version 3.3.13.