CVE-2012-1218

freelancerkit 2.35 - SQL Injection in Notes and Tickets Components

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in freelancerKit 2.35 allow remote attackers to execute arbitrary SQL commands via unspecified vectors to the (1) notes and (2) tickets components.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/73105
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/51946
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/47766

Scores

EPSS 0.0121
EPSS Percentile 65.2%

Details

CWE
CWE-89
Status published
Products (1)
freelancerkit/freelancerkit 2.35
Published Feb 21, 2012
Tracked Since Feb 18, 2026