Weer een update
Case #3785
SQL Injection via Admin Credit Routines
=== Severity Level ===
Important
=== Description ===
An attacker who can function as an authenticated admin user with the ability to apply credits to an invoice can, using specially crafted input, cause the credit routines to execute arbitrary SQL commands if the target user has a credit balance known to the attacker.
Due to the many prerequisites necessary to successfully navigate this vector, a security impact level has been assessed as "Important". Information on security ratings can be found at http://docs.whmcs.com/Security_Levels
=== Resolution ===
Download and apply the appropriate software updates to protect against these vulnerabilities; information about software update releases is provided in the "Releases" section of this Advisory.
Het hele bericht staat op http://blog.whmcs.com/?t=83303

Likes:



