RSS   Vulnerabilities for 'Simple pos'   RSS

2018-09-17
 
CVE-2018-17110

CWE-89
 

 
Simple POS 4.0.24 allows SQL Injection via a products/get_products/ columns[0][search][value] parameter in the management panel, as demonstrated by products/get_products/1.

 


Copyright 2024, cxsecurity.com

 

Back to Top