Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v8fr-p535-552p

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

SQL injection vulnerability in lib/toolkit/events/event.section.php in Symphony CMS 2.0.7 and 2.1.1 allows remote attackers to execute arbitrary SQL commands via the send-email[recipient] parameter to about/. NOTE: some of these details are obtained from third party information.

SQL injection vulnerability in lib/toolkit/events/event.section.php in Symphony CMS 2.0.7 and 2.1.1 allows remote attackers to execute arbitrary SQL commands via the send-email[recipient] parameter to about/. NOTE: some of these details are obtained from third party information.

EPSS

Процентиль: 66%
0.00505
Низкий

Дефекты

CWE-89

Связанные уязвимости

nvd
больше 15 лет назад

SQL injection vulnerability in lib/toolkit/events/event.section.php in Symphony CMS 2.0.7 and 2.1.1 allows remote attackers to execute arbitrary SQL commands via the send-email[recipient] parameter to about/. NOTE: some of these details are obtained from third party information.

EPSS

Процентиль: 66%
0.00505
Низкий

Дефекты

CWE-89