Discuz! 7 Series SQL Injection Vulnerabilities
Release date:
Updated on:
Affected Systems:
Discuz! Discuz! <= 7.2
Description:
--------------------------------------------------------------------------------
Discuz! It is an Internet forum software developed with PHP.
Discuz! In versions 7.2 and earlier, the permission view function has a logic problem with gids variable processing. As a result, anti-injection measures are bypassed, resulting in an SQL injection vulnerability. Hackers can remotely obtain all sensitive website data and even obtain website control permissions.
<* Source: vendor
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Discuz!
-------
This vulnerability affects the current discuz7 version. The official version has not yet been released and can be exploited without any conditions. This version is widely used and causes great harm. We recommend that users who use this software follow the vendor's homepage to obtain the latest version:
Http://www.discuz.net/
This article permanently updates the link address: