vendor:
Forum Userbar Plugin
by:
Mario_Vs
5.5
CVSS
MEDIUM
SQL Injection
89
CWE
Product Name: Forum Userbar Plugin
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 7
2011
MyBB Forum Userbar Plugin (Userbar v2.2)
The exploit allows an attacker to perform SQL injection by modifying the POST request in the userbarsettings.php file.
Mitigation:
The vendor should sanitize user input and use prepared statements to prevent SQL injection attacks.