CRITICAL
A SQL Injection vulnerability in get_topic_info() in sys/CODOF/Forum/Topic.php in Codoforum before 4.9 allows remote attackers (pre-authentication) to bypass the admin page via a leaked password-reset token of the admin
Published May 12, 2021
9.8
CRITICALCVSS 3.1
EPSS 4.92%
Description
Affected products
Remediation
References (7)
Change history (0)
No recorded changes yet.