Vulnerability Details CVE-2016-15034
A vulnerability was found in Dynacase Webdesk and classified as critical. Affected by this issue is the function freedomrss_search of the file freedomrss_search.php. The manipulation leads to sql injection. Upgrading to version 3.2-20180305 is able to address this issue. The patch is identified as 750a9b35af182950c952faf6ddfdcc50a2b25f8b. It is recommended to upgrade the affected component. VDB-233366 is the identifier assigned to this vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 12.8%
CVSS Severity
CVSS v3 Score 5.5
CVSS v2 Score 5.2
Products affected by CVE-2016-15034
-
cpe:2.3:a:anakeen:dynacase_webdesk:1.3.3
-
cpe:2.3:a:anakeen:dynacase_webdesk:1.4.1
-
cpe:2.3:a:anakeen:dynacase_webdesk:1.4.2
-
cpe:2.3:a:anakeen:dynacase_webdesk:1.4.3
-
cpe:2.3:a:anakeen:dynacase_webdesk:1.4.4
-
cpe:2.3:a:anakeen:dynacase_webdesk:2.0.0
-
cpe:2.3:a:anakeen:dynacase_webdesk:2.0.1
-
cpe:2.3:a:anakeen:dynacase_webdesk:2.0.2