Description
SQL injection vulnerability in usersettings.php in e107 0.7.26, and possibly other versions before 1.0.0, allows remote attackers to execute arbitrary SQL commands via the username parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin Rating by BestWebSoft Cross-Site Scripting (0.1)
WordPress Plugin Memphis Documents Library Arbitrary File Download (3.1.5)
Microsoft SQL Server CVE-2023-36730 Vulnerability (CVE-2023-36730)
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-2101)
PostgreSQL Untrusted Search Path Vulnerability (CVE-2020-10733)