Description
An exploitable SQL injection vulnerability exists in the ‘entities/fields’ page of the Rukovoditel Project Management App 2.7.2. The heading_field_id parameter in ‘‘entities/fields’ page is vulnerable to authenticated SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability, this can be done either with administrator credentials or through cross-site request forgery.
Remediation
References
Related Vulnerabilities
phpBB Improper Input Validation Vulnerability (CVE-2019-9826)
WordPress Plugin Custom 404 Pro Cross-Site Scripting (3.2.8)
Apache HTTP Server Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-3185)
MongoDb Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2018-20803)