SQL Injection in instantsoft/icms2
CVE-2023-4188
9.8CRITICAL
What is CVE-2023-4188?
A SQL Injection vulnerability exists in InstantSoft's ICMS2 versions prior to 2.16.1-git, allowing attackers to execute arbitrary SQL queries through specially crafted input. This could lead to unauthorized access to sensitive information and manipulation of the database. It is critical for users to upgrade to the latest version to mitigate potential risks associated with this vulnerability.
Affected Version(s)
instantsoft/icms2 < 2.16.1-git
