← Back to CVE List

CVE-2020-11004

Published: 2020-04-24T21:15Z
Last Modified: 2024-11-21T04:56Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
SQL Injection was discovered in Admidio before version 3.3.13. The main cookie parameter is concatenated into a SQL query without any input validation/sanitization, thus an attacker without logging in, can send a GET request with arbitrary SQL queries appended to the cookie parameter and execute SQL queries. The vulnerability impacts the confidentiality of the system. This has been patched in version 3.3.13. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt