High
CVSS 7.5
Overview
SQL injection vulnerability in the News module in Envolution allows remote attackers to execute arbitrary SQL commands via the (1) startrow and (2) catid parameter.
SQL injection vulnerability in the News module in Envolution allows remote attac...
SQL injection vulnerability in the News module in Envolution allows remote attackers to execute arbitrary SQL commands via the (1) startrow and (2) catid parameter.
This vulnerability is rated 🟠 HIGH.
Recommended actions: