CVE-2021-28242

CVE-2021-28242

SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive database information by injecting SQL commands into the "cf_name" parameter when creating a new filter under the "Collections" tab.

Source: CVE-2021-28242

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다