Description
SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive database information by injecting SQL commands into the "cf_name" parameter when creating a new filter under the "Collections" tab.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2010-2419 Vulnerability (CVE-2010-2419)
MySQL CVE-2019-2420 Vulnerability (CVE-2019-2420)
XWiki Improper Restriction of Excessive Authentication Attempts Vulnerability (CVE-2023-26476)
Masa CMS Incorrect Authorization Vulnerability (CVE-2022-47002)
WordPress Plugin Advanced Shipping Validation for WooCommerce Cross-Site Scripting (1.0.0)