Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Repute Infosystems ARMember armember-membership allows SQL Injection.This issue affects ARMember: from n/a through 3.4.11.
Problem types
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Any version
Credits
Le Ngoc Anh (Patchstack Alliance)
References
patchstack.com/...ss-armember-3-4-11-sql-injection?_s_id=cve
patchstack.com/...ss-armember-3-4-11-sql-injection?_s_id=cve