SQL injection in order and column parameters in Records.php for phpzag live add edit delete data tables records with ajax php mysql
References
Link | Resource |
---|---|
https://www.phpzag.com/live-add-edit-delete-datatables-records-with-ajax-php-mysql/ | Product Vendor Advisory |
http://www.vapidlabs.com/advisory.php?v=213 | Exploit Third Party Advisory |
http://www.openwall.com/lists/oss-security/2020/07/09/1 | Exploit Third Party Advisory |
Configurations
Information
Published : 2020-07-07 13:15
Updated : 2020-07-09 11:32
NVD link : CVE-2020-8520
Mitre link : CVE-2020-8520
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
phpzag
- phpzag