Zechat 1.5 SQL Injection via hashtag parameter
Vulnerability Description
Zechat 1.5 contains a SQL injection vulnerability in the hashtag parameter that allows unauthenticated attackers to extract database information using union-based techniques. Attackers can exploit the hashtag parameter with union-based payloads to retrieve table and column names.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-25338
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Borna nematzadeh (L0RD) or borna.nematzadeh123@gmail.com
References
More from Bylancer
View All →Affected Vendor
Bylancer
View all reports →