Multiple SQL injection vulnerabilities in the save_connection function in lib/lib.iotask.php in the iotask module in DoceboLMS 4.0.4 and previous versions allow remote authenticated users with admin or teacher privileges to execute arbitrary SQL commands via the (1) coursereportuiconfig[name] or (2) coursereportuiconfig[description] parameters to index.php.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
docebo docebolms 2.0.4 |
||
docebo docebolms |
||
docebo docebolms 4.0 |
||
docebo docebolms 2.0.5 |