Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SQL Injection was discovered in adm_program/modules/dates/dates_function.php in Admidio 3.2.5. The POST parameter dat_cat_id is concatenated into a SQL query without any input validation/sanitization.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Admidio SQL注入漏洞
Vulnerability Description
Admidio是一套免费的用于协会、团体和组织的在线会员管理系统。该系统提供用户管理、添加和更新主页以及安装和调整上面的模块等功能。 Admidio 3.2.5版本中的adm_program/modules/dates/dates_function.php文件存在SQL注入漏洞,该漏洞源于‘dat_cat_id’参数没有验证输入数据。攻击者可利用该漏洞注入SQL命令。
CVSS Information
N/A
Vulnerability Type
N/A