SOPlanning 1.45 has SQL injection via the user_list.php "by" parameter.
References
Link | Resource |
---|---|
https://medium.com/@Pablo0xSantiago/cve-2019-20179-so-planning-1-45-sql-injection-5f0050ad81d1 | Exploit Third Party Advisory |
Configurations
Information
Published : 2020-01-09 14:15
Updated : 2020-01-15 10:53
NVD link : CVE-2019-20179
Mitre link : CVE-2019-20179
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
soplanning
- soplanning