vendor:
Smart SMS & Email Manager
by:
Özkan Mustafa Akkuş (AkkuS)
8.8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Smart SMS & Email Manager
Affected Version From: 3.3
Affected Version To: 3.3
Patch Exists: YES
Related CWE: N/A
CPE: a:codecanyon:smart_sms_email_manager_ssem:3.3
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Kali Linux
2018
Smart SMS & Email Manager v3.3 – SQL Injection
The vulnerability allows an attacker to inject sql commands from the search section with 'contact_type_id' parameter in the admin panel.
Mitigation:
Input validation and sanitization should be done to prevent SQL injection attacks.