vendor:
Mumara Classic
by:
Shain Lakin
5.5
CVSS
MEDIUM
SQL Injection
89
CWE
Product Name: Mumara Classic
Affected Version From: <= 2.93
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: a:mumara:mumara_classic:2.93
Platforms Tested: CentOS 7
2021
Mumara Classic 2.93 – ‘license’ SQL Injection (Unauthenticated)
An SQL injection vulnerability in license_update.php in Mumara Classic through 2.93 allows a remote unauthenticated attacker to execute arbitrary SQL commands via the license parameter.
Mitigation:
Apply the latest patch or upgrade to a version higher than 2.93.