An issue exists in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows malicious users to gain sensitive information via the action parameter to /system/user/modules/mod_users/controller.php.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
isic.lk project isic.lk |