Description
|
|
A vulnerability has been identified in Persia BME E-Catalogue, which could be exploited by attackers to manipulate and inject SQL queries. This issue is caused by an input validation error in the "qsearch/search.asp" script when processing the "q" parameter while the "action" is set to "search", which could be exploited by malicious people to conduct SQL injection attacks and gain knowledge of sensitive information.
|