Inout Blockchain AltExchanger 1.2.1 SQL Injection



Application Details

Inout Blockchain AltExchanger is a premium and secure cryptocurrency exchange platform script, that helps the client launch a cryptocurrency exchange service online.


Vulnerability

Inout Blockchain AltExchanger is vulnerable to SQL injection.


Identification

A remote attacker could send specially crafted SQL statements to the /index.php/coins/update_marketboxslider file using the 'marketcurrency' parameter, which could allow the attacker to view, add, modify or delete information in the back-end database.


POST /index.php/coins/update_marketboxslider
PAYLOAD - marketcurrency=' OR '1'%3d'1


Detection

By turning this into a traffic file and matching rule, we are able to detect attempts to influence the vulnerable parameter with SQL injections.


Coverage

Idappcom has created signature 8022772 along with a traffic file.


References

CVE-2022-31488

Inout Blockchain AltExchanger 1.2.1 SQL Injection - Packet Storm Security

Inout Blockchain AltExchanger SQL injection - XForce


Traffic IQ

If you are concerned that your business may be at risk of this vulnerability, or others, why not try out our Traffic IQ software which can scan your defences and report any issues. Learn more here: https://www.idappcom.co.uk/traffic-iq-professional