Description
Grocery Crud 1.6.4 contains a SQL injection vulnerability in the order_by parameter that allows remote attackers to manipulate database queries. Attackers can inject malicious SQL code through the order_by[] parameter in POST requests to the ajax_list endpoint to potentially extract or modify database information.
Problem types
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Credits
TonyShavez
References
www.exploit-db.com/exploits/49985
www.exploit-db.com/exploits/49985 (ExploitDB-49985)
www.grocerycrud.com/ (Vendor Homepage)
www.grocerycrud.com/downloads (Software Download Page)
www.vulncheck.com/...ries/grocery-crud-orderby-sql-injection (VulnCheck Advisory: Grocery crud 1.6.4 - 'order_by' SQL Injection)