Vulnerability CVE-2015-10069


Published: 2023-01-19

Description:
A vulnerability was found in viakondratiuk cash-machine. It has been declared as critical. This vulnerability affects the function is_card_pin_at_session/update_failed_attempts of the file machine.py. The manipulation leads to sql injection. The name of the patch is 62a6e24efdfa195b70d7df140d8287fdc38eb66d. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-218896.

Type:

CWE-89

(Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'))

 References:
https://github.com/viakondratiuk/cash-machine/commit/62a6e24efdfa195b70d7df140d8287fdc38eb66d
https://vuldb.com/?ctiid.218896
https://vuldb.com/?id.218896

Copyright 2023, cxsecurity.com

 

Back to Top