Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Profile Builder Pro allows Blind SQL Injection.This issue affects Profile Builder Pro: from n/a before 3.14.0.
Problem types
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Any version before 3.14.0
Credits
0xd4rk5id3 | Patchstack Bug Bounty Program
References
patchstack.com/...13-9-sql-injection-vulnerability?_s_id=cve