VDB
Sign up
CRITICAL9.8

GHSA-q4hw-62mx-q37w

MetalGenix GeniXCMS vulnerable to SQL Injection

Details

Multiple SQL injection vulnerabilities in inc/lib/User.class.php in MetalGenix GeniXCMS before 0.0.3-patch allow remote attackers to execute arbitrary SQL commands via the (1) email parameter or (2) userid parameter to register.php.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/genix/cms
Introduced in: 0

No fixed version published yet for genix/cms (composer). Pin to a known-safe version or switch to an alternative.

References