kiCode111 like-girl SQL Injection Vulnerability in CopyadminPost.php

Vulnerability

A critical SQL injection vulnerability has been identified in kiCode111 like-girl version 5.2.0. The issue arises in the file /admin/CopyadminPost.php, where the 'icp/Copyright' argument is manipulated, leading to unauthorized SQL command execution. This vulnerability can be exploited remotely and requires authenticated access.

Impact

Exploitation of this vulnerability allows for SQL injection, where an attacker can interfere with the application's database queries. This could lead to unauthorized data access, data manipulation, or in some cases, executing administrative operations on the database.

Reproduction

To reproduce this vulnerability, log into the application as an admin. Once authenticated, send a POST request to /admin/CopyadminPost.php with the 'icp' parameter set to a value that will be concatenated into the SQL query. The 'Copyright' parameter should also be included. After sending the request, use a tool like sqlmap to automate the exploitation process and verify the SQL injection vulnerability.

Added: Jun 12, 2025, 2:31 AM
Updated: Jun 12, 2025, 2:31 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.1
remediation
0.0
relevance
0.2
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.