Description
SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive database information by injecting SQL commands into the "cf_name" parameter when creating a new filter under the "Collections" tab.
Remediation
References
Related Vulnerabilities
MySQL CVE-2021-35642 Vulnerability (CVE-2021-35642)
Moodle Generation of Error Message Containing Sensitive Information Vulnerability (CVE-2024-48896)
WordPress Plugin NextCellent Gallery-NextGEN Legacy Cross-Site Scripting (1.9.27)
WordPress Plugin WordPress Backup to Dropbox Cross-Site Scripting (4.0)