Description
SQL injection vulnerability in the Search::setJsonAlert method in OSClass before 3.4.3 allows remote attackers to execute arbitrary SQL commands via the alert parameter in a search alert subscription action.
Remediation
References
Related Vulnerabilities
WordPress Plugin Contus HD FLV Player 'process-sortable.php' SQL Injection (1.3)
WordPress Plugin XO Event Calendar Cross-Site Scripting (2.3.6)
WordPress Plugin Timetable and Event Schedule by MotoPress Unspecified Vulnerability (2.4.3)
MySQL CVE-2024-21244 Vulnerability (CVE-2024-21244)
PmWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2011-4453)