CVE-2018-17843
SQL injection exists in ADD Clicking MLM Software 1.0, Binary MLM Software 1.0, Level MLM Software 1.0, Singleleg MLM Software 1.0, Autopool MLM Software 1.0, Investment MLM Software 1.0, Bidding MLM Software 1.0, Moneyorder MLM Software 1.0, Repurchase MLM Software 1.0, and Gift MLM Software 1.0 via the member/readmsg.php msg_id parameter, the member/tree.php pid parameter, or the member/downline.php m_id parameter.
Published:May 24, 2019
Last Modified:Nov 21, 2024
EPS:May 24, 2019
EPSS Score:0.00694
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Mlmsoftwarez
Product
Add Clicking Mlm Software
Mlmsoftwarez
Add Clicking Mlm Software
Vendor
Mlmsoftwarez
Product
Autopool Mlm Software
Mlmsoftwarez
Autopool Mlm Software
Vendor
Mlmsoftwarez
Product
Bidding Mlm Software
Mlmsoftwarez
Bidding Mlm Software
Vendor
Mlmsoftwarez
Product
Binary Mlm Software
Mlmsoftwarez
Binary Mlm Software
Vendor
Mlmsoftwarez
Product
Gift Mlm Software
Mlmsoftwarez
Gift Mlm Software
Vendor
Mlmsoftwarez
Product
Investmen Mlm Software
Mlmsoftwarez
Investmen Mlm Software
Vendor
Mlmsoftwarez
Product
Level Mlm Software
Mlmsoftwarez
Level Mlm Software
Vendor
Mlmsoftwarez
Product
Moneyorder Mlm Software
Mlmsoftwarez
Moneyorder Mlm Software
Vendor
Mlmsoftwarez
Product
Repurchase Mlm Software
Mlmsoftwarez
Repurchase Mlm Software
Vendor
Mlmsoftwarez
Product
Singleleg Mlm Software
Mlmsoftwarez
Singleleg Mlm Software
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
