Description
SQL injection vulnerability in administration/profiles.php in BoonEx Dolphin 7.1.4 and earlier allows remote authenticated administrators to execute arbitrary SQL commands via the members[] parameter. NOTE: this can be exploited by remote attackers by leveraging CVE-2014-4333.
Remediation
References
Related Vulnerabilities
WordPress Plugin Web to Print Online Designer Security Bypass (2.3.0)
MySQL CVE-2021-2076 Vulnerability (CVE-2021-2076)
Next.js Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2025-30218)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-6610)
XWikiplatform Missing Authorization Vulnerability (CVE-2024-31981)