CVE-2021-30177 Information
Jun 07, 2022
cve
Description
There is a SQL Injection vulnerability in PHP-Nuke 8.3.3 in the User Registration section leading to remote code execution. This occurs because the U.S. state is not validated to be two letters and the OrderBy field is not validated to be one of LASTNAME CITY or STATE.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://gist.github.com/stacksmasher007/41e946fc9a5a2f0b6950626cc9d43d47
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: