Joomla扩展 – ordasoft.com – OrdaSoft Simple Membership 版本低于7.4.0中存在未认证的SQL注入漏洞。site/simplemembership.php中,当参数task=checkLoginPass被调用时,没有进行任何身份验证或访问控制检查。该处理程序通过Joomla通用的、不进行数据清理的输入过滤器读取登录请求参数,该过滤器仅剥离HTML/脚本标签,但不会对引号或SQL语法进行任何处理,随后将该参数直接拼接到查询字符串中,既未进行转义,也未使用参数化查询。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ordasoft.com | OrdaSoft Simple Membership extension for Joomla | 1.0.0-7.4.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet