High
CVSS 7.5
Overview
SQL injection vulnerability in calendar.php for Invision Power Board 1.3 allows remote attackers to execute arbitrary SQL commands via the m parameter, which sets the $this->chosen_month variable.
SQL injection vulnerability in calendar.php for Invision Power Board 1.3 allows ...
SQL injection vulnerability in calendar.php for Invision Power Board 1.3 allows remote attackers to execute arbitrary SQL commands via the m parameter, which sets the $this->chosen_month variable.
This vulnerability is rated 🟠 HIGH.
Recommended actions: