First published: Mon Mar 09 2020(Updated: )
SQL Injection exists in Advanced Newsletter Magento extension before 2.3.5 via the /store/advancednewsletter/index/subscribeajax/an_category_id/ PATH_INFO.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Magento Advanced Newsletter | <2.3.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.