GHSA-4pwx-3vc3-jq9gHighCVSS 8.2
E-Registrasi Pencak Silat 18.10 contains an SQL injection vulnerability that allows...
🔗 CVE IDs covered (1)
📋 Description
E-Registrasi Pencak Silat 18.10 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id_partai parameter. Attackers can send GET requests to monitor_nilai.php with crafted SQL payloads in the id_partai parameter to extract sensitive database information including admin credentials and user data.
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2018-25385
- https://sourceforge.net/projects/eregistrasi-kejuaraan-silat
- https://sourceforge.net/projects/eregistrasi-kejuaraan-silat/files/latest/download
- https://www.exploit-db.com/exploits/45582
- https://www.vulncheck.com/advisories/e-registrasi-pencak-silat-sql-injection-via-id-partai
- https://github.com/advisories/GHSA-4pwx-3vc3-jq9g