Description
CubeCart before 6.1.13 has SQL Injection via the validate[] parameter of the "I forgot my Password!" feature.
Remediation
References
Related Vulnerabilities
WordPress Plugin Login Block IPs Cross-Site Request Forgery (1.0.0)
Moodle Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2018-1133)
Oracle JRE Insecure Storage of Sensitive Information Vulnerability (CVE-2024-21211)
YetiForce CRM Improper Input Validation Vulnerability (CVE-2021-4117)