An issue was discovered in flatCore before 2.0.0 build 139. A time-based blind SQL injection was identified in the selected_folder HTTP request body parameter for the acp interface. The affected parameter (which retrieves the file contents of the specified folder) was found to be accepting malicious user input without proper sanitization, thus leading to SQL injection. Database related information can be successfully retrieved.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T19:14:09.147Z
Reserved: 2021-01-11T00:00:00
Link: CVE-2021-23837

No data.

Status : Modified
Published: 2021-01-15T07:15:14.097
Modified: 2024-11-21T05:51:54.713
Link: CVE-2021-23837

No data.

No data.