Description
|
|
Multiple vulnerabilities have been discovered in the Advanced Forum Signatures plugin for MyBB, which can be exploited by malicious users to conduct SQL injection attacks.
Input passed to the "afs_type", "afs_background", "afs_showonline", "afs_bar_left", "afs_bar_center", "afs_bar_right", and "afs_full_line1" through "afs_full_line6" parameters in signature.php is not properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
The vulnerabilities are confirmed in version 2.0.4. Other versions may also be affected.
|