Description
SQL injection vulnerability in OSK Advance-Flow 4.41 and earlier and Advance-Flow Forms 4.41 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
References (2)
Core 2
Core References
Third Party Advisory third-party-advisory
x_refsource_jvndb
http://jvndb.jvn.jp/jvndb/JVNDB-2014-000099
Third Party Advisory third-party-advisory
x_refsource_jvn
http://jvn.jp/en/jp/JVN20812625/index.html
Scores
EPSS
0.0116
EPSS Percentile
64.0%
Details
CWE
CWE-89
Status
published
Products (2)
kk-osk/advance-flow
< 4.41
kk-osk/advance-flow_forms
< 4.41
Published
Aug 19, 2014
Tracked Since
Feb 18, 2026