Vulnerability Description
Inout Blockchain AltExchanger 1.2.1 and Inout Blockchain FiatExchanger 2.2.1 allow Chart/TradingView/chart_content/master.php symbol SQL injection.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Inoutscripts | Blockchain Altexchanger | 1.2.1 |
| Inoutscripts | Blockchain Fiatexchanger | 2.2.1 |
Related Weaknesses (CWE)
References
- https://github.com/bigb0x/CVEs/blob/main/Blockchain-AltExchanger-121-sqli.mdExploitThird Party Advisory
- https://github.com/bigb0x/CVEs/blob/main/Inout-Blockchain-FiatExchanger-221-sqliExploitThird Party Advisory
- https://github.com/bigb0x/CVEs/blob/main/Blockchain-AltExchanger-121-sqli.mdExploitThird Party Advisory
- https://github.com/bigb0x/CVEs/blob/main/Inout-Blockchain-FiatExchanger-221-sqliExploitThird Party Advisory
FAQ
What is CVE-2022-31487?
CVE-2022-31487 is a vulnerability with a CVSS score of 7.5 (HIGH). Inout Blockchain AltExchanger 1.2.1 and Inout Blockchain FiatExchanger 2.2.1 allow Chart/TradingView/chart_content/master.php symbol SQL injection.
How severe is CVE-2022-31487?
CVE-2022-31487 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-31487?
Check the references section above for vendor advisories and patch information. Affected products include: Inoutscripts Blockchain Altexchanger, Inoutscripts Blockchain Fiatexchanger.