HIGH
Multiple SQL injection vulnerabilities in CuteFlow 2.10.0 allow remote authenticated users to execute arbitrary SQL commands via the (1) listid parameter to pages/editmailinglist_step1.php, the (2) userid parameter to pages/edituser.php, the (3) fieldid parameter to pages/editfield.php, and the (4) templateid to pages/edittemplate_step1.php
Published Apr 2, 2008
7.5
HIGHCVSS 2.0
EPSS 1.00%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.