Description
An exploitable SQL injection vulnerability exists in the ‘entities/fields’ page of the Rukovoditel Project Management App 2.7.2. The heading_field_id parameter in ‘‘entities/fields’ page is vulnerable to authenticated SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability, this can be done either with administrator credentials or through cross-site request forgery.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Maintenance Mode & Site Under Construction Security Bypass (1.8.1)
WordPress Plugin Custom Background 'uploadify.php' Arbitrary File Upload (1.01)
WordPress Plugin Ads Pro-Multi-Purpose WordPress Advertising Manager Multiple Vulnerabilities (3.4)
WordPress Plugin Media File Manager Advanced Multiple Vulnerabilities (1.1.5)