TaskFreak SQL Injection and Cross Site Scripting Vulnerabilities
Description
Multiple vulnerabilities have been identified in TaskFreak, which could be exploited by attackers to disclose sensitive information or inject SQL queries. These issues are caused by input validation errors in the "include/classes/tzn_user.php" and "logout.php" scripts when processing the "password" and "tznMessage" parameters, which could be exploited to conduct SQL injection or cross site scripting attacks.
Vulnerable Products
Vulnerable Software: TaskFreak version 0.6.3 and prior