Description
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands via the searchFriends function to friends.inc.php.
Remediation
References
Related Vulnerabilities
Plone CMS Improper Input Validation Vulnerability (CVE-2011-4462)
Apache HTTP Server Out-of-bounds Write Vulnerability (CVE-2020-35452)
MySQL CVE-2018-2667 Vulnerability (CVE-2018-2667)
Moodle Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2018-16854)
WordPress Plugin BetterDocs-Best Documentation & Knowledge Base Cross-Site Scripting (1.9.1)