CVE-2018-17843 Information
Feb 14, 2021
cve
Description
SQL injection exists in ADD Clicking MLM Software 1.0 Binary MLM Software 1.0 Level MLM Software 1.0 Singleleg MLM Software 1.0 Autopool MLM Software 1.0 Investment MLM Software 1.0 Bidding MLM Software 1.0 Moneyorder MLM Software 1.0 Repurchase MLM Software 1.0 and Gift MLM Software 1.0 via the member/readmsg.php msg_id parameter the member/tree.php pid parameter or the member/downline.php m_id parameter.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://www.exploit-db.com/author/?a=8844 https://www.exploit-db.com/exploits/45511
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: