RULE(RULE ID:333474)

Rule General Information
Release Date: 2021-04-16
Rule Name: K-iwi Framework 1775 SQL Injection Vulnerability (CVE-2018-18755)
Severity:
CVE ID:
Rule Protection Details
Description: K-iwi Framework 1775 has SQL Injection via the admin/user/group/update user_group_id parameter or the admin/user/user/update user_id parameter.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference: ExploitDB:45735
http://packetstormsecurity.com/files/150016/K-iwi-Framework-1775-SQL-Injection.html
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
http://www.k-iwi.com/