vendor:
Employee Work Schedule Multicalendar
by:
Özkan Mustafa Akkus (AkkuS)
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Employee Work Schedule Multicalendar
Affected Version From: 5.9
Affected Version To: 5.9
Patch Exists: NO
Related CWE: N/A
CPE: a:codecanyon:employee_work_schedule_multicalendar
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Kali Linux
2018
EWS 5.9 – ‘search’ SQL Injection
The vulnerability allows an attacker to inject sql commands from the search section with 'cal_id' parameter.
Mitigation:
Input validation and sanitization should be done to prevent SQL injection attacks.