A vulnerability classified as critical has been found in Demokratian. This affects an unknown part of the file install/install3.php. The manipulation leads to privilege escalation. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.
References
Link | Resource |
---|---|
https://alquimistadesistemas.com/sql-injection-y-archivo-peligroso-en-demokratian | Exploit Patch Third Party Advisory |
https://bitbucket.org/csalgadow/demokratian_votaciones/commits/0d073ee461edd5f42528d41e00bf0a7b22e86bb3 | Patch Third Party Advisory |
https://vuldb.com/?id.159435 | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2022-06-07 18:15
Updated : 2022-06-11 03:54
NVD link : CVE-2020-36542
Mitre link : CVE-2020-36542
CVE.ORG link : CVE-2020-36542
JSON object : View
Products Affected
demokratian
- demokratian
CWE
CWE-269
Improper Privilege Management