vendor:
vBizz
by:
Ihsan Sencan
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: vBizz
Affected Version From: 1.0.7
Affected Version To: 1.0.7
Patch Exists: NO
Related CWE:
CPE: a:wdmtech:vbizz:1.0.7
Platforms Tested: Windows 7 64-bit, Kali Linux 64-bit
2019
Joomla! Component vBizz 1.0.7 – SQL Injection
The Joomla! Component vBizz version 1.0.7 is vulnerable to SQL Injection. An attacker can exploit this vulnerability to execute arbitrary SQL commands on the target system.
Mitigation:
Update to the latest version of the software or apply a patch provided by the vendor. Use input validation and parameterized queries to prevent SQL Injection attacks.