Description
AbanteCart 1.2.8 allows SQL Injection via the source_language parameter to admin/controller/pages/localisation/language.php and core/lib/language_manager.php, or via POST data to admin/controller/pages/tool/backup.php and admin/model/tool/backup.php.
Remediation
References
Related Vulnerabilities
WordPress Plugin Adminer Security Bypass (1.4.5)
PHP Improper Handling of Exceptional Conditions Vulnerability (CVE-2014-1943)
WordPress Plugin Advanced Custom Fields (ACF) Arbitrary File Upload (5.12.2)
MediaWiki CVE-2023-45367 Vulnerability (CVE-2023-45367)
WordPress Plugin WP Idea Stream Cross-Site Scripting (2.1.1)