CVE-2018-25071
Description
A vulnerability was found in roxlukas LMeve up to 0.1.58. It has been rated as critical. Affected by this issue is the function insert_log of the file wwwroot/ccpwgl/proxy.php. The manipulation of the argument fetch leads to sql injection. Upgrading to version 0.1.59-beta is able to address this issue. The patch is identified as c25ff7fe83a2cda1fcb365b182365adc3ffae332. It is recommended to upgrade the affected component. VDB-217610 is the identifier assigned to this vulnerability.
- CVSS Version 3.1
- CVSS Version 3.0
- CVSS Version 2.0
nvd
CVE ID: CVE-2018-25071
Base Score: 9.8
Base Severity: CRITICAL
Vector String:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Impact Score: 5.9
Exploitability Score: 3.9
vuldb
CVE ID: CVE-2018-25071
Base Score: 5.5
Base Severity: MEDIUM
Vector String:CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Impact Score: 3.4
Exploitability Score: 2.1
vuldb
CVE ID: CVE-2018-25071
Base Score: 5.5
Base Severity: MEDIUM
Vector String:CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
vuldb
CVE ID: CVE-2018-25071
Base Score: 5.2
Base Severity: MEDIUM
Vector String:AV:A/AC:L/Au:S/C:P/I:P/A:P