CVE-2017-6492

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
05/03/2017
Last modified:
20/04/2025

Description

SQL Injection was discovered in adm_program/modules/dates/dates_function.php in Admidio 3.2.5. The POST parameter dat_cat_id is concatenated into a SQL query without any input validation/sanitization.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:admidio:admidio:3.2.5:*:*:*:*:*:*:*