First published: Tue Jan 15 2019(Updated: )
CubeCart before 6.1.13 has SQL Injection via the validate[] parameter of the "I forgot my Password!" feature.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cubecart Cubecart | <6.1.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-20716 refers to a SQL Injection vulnerability in CubeCart versions before 6.1.13.
CVE-2018-20716 has a severity score of 9.8 (critical).
To fix CVE-2018-20716, you should update CubeCart to version 6.1.13 or later.
The affected software for CVE-2018-20716 is CubeCart versions before 6.1.13.
The CWE ID for CVE-2018-20716 is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command).