CVE
- Id
- 103312
- CVE No.
- CVE-2017-6492
- Status
- Candidate
- Description
- SQL Injection was discovered in adm_program/modules/dates/dates_function.php in Admidio 3.2.5. The POST parameter dat_cat_id is concatenated into a SQL query without any input validation/sanitization.
- Phase
- Assigned (20170305)
- Votes
- None (candidate not yet proposed)
- Comments