SQL Injection vulnerability in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows malicious users to execute arbitrary commands via the username parameter to /system/user/modules/mod_users/controller.php.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
isic.lk project isic.lk |