vendor:
FB Inboxer
by:
Özkan Mustafa Akkuş (AkkuS)
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: FB Inboxer
Affected Version From: 1.2
Affected Version To: 1.2
Patch Exists: YES
Related CWE: N/A
CPE: a:codecanyon:fb_inboxer:1.2
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Kali Linux
2018
FB Inboxer 1.2 – ‘search_field’ SQL Injection
The vulnerability allows an attacker to inject sql commands from the search section with 'search_field' parameter in the management panel.
Mitigation:
Input validation and sanitization should be done to prevent SQL injection attacks.