Vulnerability Description
SQL injection vulnerability in Sharetronix before 3.4 allows remote authenticated users to execute arbitrary SQL commands via the invite_users[] parameter to the /invite page for a group.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sharetronix | Sharetronix | <= 3.3 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/126859/Sharetronix-3.3-Cross-Site-Request-FExploit
- http://www.securityfocus.com/bid/67680
- https://www.htbridge.com/advisory/HTB23214Exploit
- http://packetstormsecurity.com/files/126859/Sharetronix-3.3-Cross-Site-Request-FExploit
- http://www.securityfocus.com/bid/67680
- https://www.htbridge.com/advisory/HTB23214Exploit
FAQ
What is CVE-2014-3415?
CVE-2014-3415 is a vulnerability with a CVSS score of 6.5 (MEDIUM). SQL injection vulnerability in Sharetronix before 3.4 allows remote authenticated users to execute arbitrary SQL commands via the invite_users[] parameter to the /invite page for a group.
How severe is CVE-2014-3415?
CVE-2014-3415 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-3415?
Check the references section above for vendor advisories and patch information. Affected products include: Sharetronix Sharetronix.