Web / CMS

SQL / NoSQL Injection

SQL Injection vulnerability in textMessage field in ChatEngine 1.0

SQL Injection vulnerability in textMessage field in ChatEngine 1.0 The Application does not sanitize or escape txtmessage parameter, making it vulnerable to sql injection.

7.5
/ 10
High
CVSS v3.1
ADVISORY ID
PS78
PUBLISHED
2023-07-05
CVE IDs
CVE-2023-30325
VENDORS
wliang6
PUBLIC EXPLOIT
None indexed
CWE
CWE-89
PRODUCT
ChatEngine 1.0
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

SQL Injection vulnerability in textMessage field in ChatEngine 1.0

The Application does not sanitize or escape txtmessage parameter, making it vulnerable to sql injection. An attacker can put payload in the username field to exploit the sql injection vulnerability.

Vulnerability details

Vulnerability details

CVE-2023-30325
CWE-89
High | 7.5

SQL Injection vulnerability in textMessage field in ChatEngine 1.0 The Application does not sanitize or escape txtmessage parameter, making it vulnerable to sql injection.

Auth:
None (remote)
Impact:
Sensitive data disclosure
DISCLOSURE

Disclosure timeline

2023-04-01 Reported On

2023-07-06 Made Public On

Fixed On: Not Fixed

Credits

Akshat Singhal