Description
|
|
A vulnerability has been reported in FluxBB, which can be exploited by malicious users to conduct SQL injection attacks.
Input passed via the "req_new_email" parameter to profile.php (when "action" is set to "change_email") is not properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
The vulnerability is reported in versions prior to 1.4.13 and 1.5.7.
|