WebTareas
cpe:2.3:a:webtareas_project:webtareas:*:*:*:*:*:*:*
- 2.4
A SQL injection vulnerability has been identified in WebTareas version 2.4. The issue resides in the webTareasSID cookie parameter, allowing unauthenticated attackers to manipulate database queries. Exploitation of this vulnerability can lead to error-based and time-based blind SQL injection, enabling attackers to extract database information and potentially access sensitive system data.
Exploitation of this vulnerability allows for unauthorized SQL injection, which can be used to manipulate database queries, extract information from the database, and potentially access sensitive system data.
The vulnerability can be reproduced by sending a GET request to the webTareas administration page with a crafted webTareasSID cookie. The payload should include SQL injection techniques, such as error-based or time-based blind SQL injection, to exploit the vulnerability and extract database information.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.