Description
|
|
Chapp has discovered a vulnerability in the kitForm extension for KeepInTouch, which can be exploited by malicious people to conduct SQL injection attacks.
Input passed via the "sorter_value" POST parameter to sorter.php (when "sorter_table" is set to "mod_kit_form" and "rowID" is set) is not properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
The vulnerability is confirmed in version 0.43.
|