CVE-2018-1999022
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
PEAR HTML_QuickForm version 3.2.14 contains an eval injection (CWE-95) vulnerability in HTML_QuickForm's getSubmitValue method, HTML_QuickForm's validate method, HTML_QuickForm_hierselect's _setOptions method, HTML_QuickForm_element's _findValue method, HTML_QuickForm_element's _prepareValue method. that can result in Possible information disclosure, possible impact on data integrity and execution of arbitrary code. This attack appear to be exploitable via A specially crafted query string could be utilised, e.g. http://www.example.com/admin/add_practice_type_id[1]=fubar%27])%20OR%20die(%27OOK!%27);%20//&mode=live. This vulnerability appears to have been fixed in 3.2.15.
PEAR HTML_QuickForm 3.2.14 contiene una vulnerabilidad de inyección de eval (CWE-95) en el método getSubmitValue de HTML_QuickForm el método validate de HTML_QuickForm, el método _setOptions de HTML_QuickForm_hierselect, el método _findValue de HTML_QuickForm_element y en el método _prepareValue de HTML_QuickForm_element que puede resultar en una posible divulgación de información, un posible impacto en la integridad de los datos y en la ejecución de código arbitrario. Este ataque parece ser explotable empleando una cadena de consulta especialmente manipulada, por ejemplo: http://www.example.com/admin/add_practice_type_id[1]=fubar%27])%20OR%20die(%27OOK!%27);%20//mode=live. La vulnerabilidad parece haber sido solucionada en la versión 3.2.15.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-07-23 CVE Reserved
- 2018-07-23 CVE Published
- 2024-09-16 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://civicrm.org/advisory/civi-sa-2018-07-remote-code-execution-in-quickform | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://blog.pear.php.net/2018/07/19/security-vulnerability-announcement-html_quickform | 2018-10-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Html Quickform Project Search vendor "Html Quickform Project" | Html Quickform Search vendor "Html Quickform Project" for product "Html Quickform" | 3.2.14 Search vendor "Html Quickform Project" for product "Html Quickform" and version "3.2.14" | - |
Affected
| ||||||
Civicrm Search vendor "Civicrm" | Civicrm Search vendor "Civicrm" for product "Civicrm" | <= 4.6.37 Search vendor "Civicrm" for product "Civicrm" and version " <= 4.6.37" | - |
Affected
| ||||||
Civicrm Search vendor "Civicrm" | Civicrm Search vendor "Civicrm" for product "Civicrm" | 5.3.0 Search vendor "Civicrm" for product "Civicrm" and version "5.3.0" | - |
Affected
|