CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
Percentile
78.3%
Zero Science Lab reports:
Input passed via the parameter ‘sortby’ is not properly
sanitised before being returned to the user or used in SQL queries.
This can be exploited to manipulate SQL queries by injecting
arbitrary SQL code. The param ‘num’ is vulnerable to a XSS issue
where the attacker can execute arbitrary HTML and script code in
a user’s browser session in context of an affected site.