Web / CMS
SQL / NoSQL Injection
SQL Injection in chatWindow functionality in ChatEngine 1.0
SQL Injection in chatWindow functionality in ChatEngine 1.0 The Application does not sanitize or escape username parameter, making it vulnerable to sql injection.
.png)
Overview
SQL Injection in chatWindow functionality in ChatEngine 1.0
The Application does not sanitize or escape username parameter, making it vulnerable to sql injection. An attacker can put payload in the username field to exploit the sql injection vulnerability.
Vulnerability details
SQL Injection in chatWindow functionality in ChatEngine 1.0 The Application does not sanitize or escape username parameter, making it vulnerable to sql injection. An attacker can put payload in the username field to exploit the sql injection vulnerability.
Disclosure timeline
2023-04-01 Reported On
2023-07-06 Made Public On
Fixed On: Not Fixed
References
Credits
Akshat Singhal
















