Description
A SQL Injection vulnerability was discovered in AbanteCart 1.4.0 in the update() function in public_html/admin/controller/responses/listing_grid/email_templates.php. The vulnerability is exploitable via the id parameter.
Remediation
References
Related Vulnerabilities
Magento Improper Authorization Vulnerability (CVE-2020-24403)
MySQL CVE-2018-2583 Vulnerability (CVE-2018-2583)
MySQL CVE-2018-2781 Vulnerability (CVE-2018-2781)
WordPress Plugin wpForo Forum SQL Injection (2.3.3)
WordPress Plugin Apptivo Business Site CRM Multiple Cross-Site Scripting Vulnerabilities (1.2.9)