Description
AMSS++ version 4.31 contains a SQL injection vulnerability in the mail module's maildetail.php script through the 'id' parameter. Attackers can manipulate the 'id' parameter in /modules/mail/main/maildetail.php to inject malicious SQL queries and potentially access or modify database contents.
Problem types
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Credits
indoushka
References
www.exploit-db.com/exploits/48109 (ExploitDB-48109)
www.vulncheck.com/advisories/amss-v-id-sql-injection (VulnCheck Advisory: AMSS++ v 4.31 - 'id' SQL Injection)