Vulnerability Description
OpenSNS v6.1.0 allows SQL Injection via the index.php?s=/ucenter/Config/ uid parameter because of the getNeedQueryData function in Application/Common/Model/UserModel.class.php.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Opensns | Opensns | 6.1.0 |
Related Weaknesses (CWE)
References
- https://github.com/kikulo/DebugOpen/blob/master/OpenSNSv6.1.0/main.mdExploitThird Party Advisory
- https://github.com/kikulo/DebugOpen/blob/master/OpenSNSv6.1.0/main.mdExploitThird Party Advisory
FAQ
What is CVE-2019-14266?
CVE-2019-14266 is a vulnerability with a CVSS score of 8.8 (HIGH). OpenSNS v6.1.0 allows SQL Injection via the index.php?s=/ucenter/Config/ uid parameter because of the getNeedQueryData function in Application/Common/Model/UserModel.class.php.
How severe is CVE-2019-14266?
CVE-2019-14266 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-14266?
Check the references section above for vendor advisories and patch information. Affected products include: Opensns Opensns.