xbtitFM 4.1.18 Unauthenticated SQL Injection in shoutedit.php
Vulnerability Description
xbtitFM 4.1.18 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database queries by injecting malicious SQL code through the msgid parameter. Attackers can send crafted requests to /shoutedit.php with EXTRACTVALUE functions to extract database names, user credentials, and password hashes from the underlying database.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-58309
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- xbtitFM Team
References
Affected Vendor
xbtitfm
View all reports →