Trol InterMedia 2ClickPortal Boolean-Based Blind SQL Injection Vulnerability

Vulnerability

A boolean-based blind SQL injection vulnerability has been identified in Trol InterMedia's 2ClickPortal software, affecting all versions prior to 7.14.3. The issue arises from improper neutralization of input provided by an unauthorized user into the 'changes__reference_id' parameter in the URL, allowing for SQL injection attacks that exploit boolean logic to extract information from the database.

Impact

Exploitation of this vulnerability allows for boolean-based blind SQL injection, where an attacker can manipulate SQL queries to the database and potentially extract or modify data.

Remediation

Users can upgrade to version 7.14.3 of 2ClickPortal to address this vulnerability.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.