Description
SQL injection vulnerability in the Group Promotions module in the admin control panel in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Remediation
References
Related Vulnerabilities
EspoCRM Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-5965)
WordPress Plugin Slider by 10Web-Responsive Image Slider Cross-Site Request Forgery (1.2.22)
SharePoint CVE-2024-43464 Vulnerability (CVE-2024-43464)
Python CVE-2020-27619 Vulnerability (CVE-2020-27619)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-5304)