Skip to content

Fix sql injection in sql-admin-manager plugin#1423

Merged
peace-maker merged 1 commit intoalliedmodders:masterfrom
peace-maker:admin-manager-sqli
Feb 2, 2021
Merged

Fix sql injection in sql-admin-manager plugin#1423
peace-maker merged 1 commit intoalliedmodders:masterfrom
peace-maker:admin-manager-sqli

Conversation

@peace-maker
Copy link
Member

This bug was found as part of justCTF 2020 in the PainterHell challenge by cypis. Thank you!

Admins with the root flag could inject their own queries towards the admin database connection.

The sql-admin-manager plugin is disabled by default.

This bug was found as part of justCTF 2020 in the PainterHell challenge by cypis. Thank you!

Admins with the root flag could inject their own queries towards the admin database connection.

The sql-admin-manager plugin is disabled by default.
@peace-maker peace-maker merged commit 91a1fd0 into alliedmodders:master Feb 2, 2021
@peace-maker peace-maker deleted the admin-manager-sqli branch February 2, 2021 10:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants