Thrive Smart Home 1.1 - 'Smart Home' Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vulnerability Description
Thrive Smart Home 1.1 contains an SQL injection vulnerability in the checklogin.php endpoint that allows unauthenticated attackers to bypass authentication by manipulating the 'user' POST parameter. Attackers can inject malicious SQL code like ' or 1=1# to manipulate login queries and gain unauthorized access to the application.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-25325
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- LiquidWorm as Gjoko Krstic of Zero Science Lab
References
- https://www.exploit-db.com/exploits/47814
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5554.php
- https://packetstorm.news/files/id/155797
- https://cxsecurity.com/issue/WLB-2020010019
- https://exchange.xforce.ibmcloud.com/vulnerabilities/173728
- https://www.vulncheck.com/advisories/thrive-smart-home-smart-home-improper-limitation-o
Affected Vendor
Thrive
View all reports →