SQL Injection Vulnerabilities Found in Spip Web Framework by SPIP
CVE-2022-28961
8.8HIGH
What is CVE-2022-28961?
Multiple SQL injection vulnerabilities were identified in Spip Web Framework versions 3.1.13 and earlier. These vulnerabilities can be exploited through the 'lier_trad' and 'where' parameters at the /ecrire endpoint, potentially allowing unauthorized access to sensitive data. It is crucial for users of these affected versions to apply the necessary security updates to mitigate risks.